ScMinidriver Zig Reference Documentation
ScMinidriver
Current Version: 11.6.1
Chilkat.ScMinidriver
Use the Windows smart-card minidriver layer to access card capabilities
without working directly at the APDU level.
Enumerate and inspect smart-card certificates, key containers, container
indexes, key types, and related card state.
Authenticate to the card with the required PIN before accessing protected
private-key operations or card objects.
Sign data using private keys that remain on the smart card, including
workflows where the private key is non-exportable.
Generate or import RSA and ECC keys into supported card containers when
the card policy allows it.
Link a smart-card certificate to other Chilkat classes so PDF, XML,
CMS/PKCS7, S/MIME, or other signing operations can use the card-backed
private key.
For an extended overview, see
ScMinidriver Class Overview.
Access smart-card certificates, key containers, PINs, files, and on-card signing.
Chilkat.ScMinidriver is a smart-card integration class for
applications that need card minidriver access to certificates, key
containers, PIN authentication, card files, and on-card signing. It can
retrieve and link smart-card certificates for use in other Chilkat signing
classes, generate or import RSA and ECC keys, sign data directly, inspect
card and container state, and manage selected card files and certificates.
Connect through minidriver
Certificates and containers
PIN authentication
On-card signing
Key generation and import
Use with Chilkat signing
ScMinidriver for Windows card-minidriver certificate
and key-container operations; use Chilkat.SCard for direct
PC/SC APDU-level work, and Chilkat.Pkcs11 for PKCS#11 token or
HSM sessions.
Object Creation
// Add the package once:
// zig fetch --save https://chilkatdownload.com/11.6.1/chilkat-zig-11.6.1.tar.gz
// and in build.zig:
// const chilkat = b.dependency("chilkat", .{ .target = target, .optimize = optimize });
// exe.root_module.addImport("chilkat", chilkat.module("chilkat"));
const chilkat = @import("chilkat");
// Once per process, before any other Chilkat call:
try chilkat.unlockBundle("Anything for 30-day trial");
const sc_minidriver = try chilkat.ScMinidriver.init();
defer sc_minidriver.deinit();Creates the underlying native Chilkat object. ScMinidriver is a one-pointer struct passed by value; copying it copies the handle (two names for one object). Returns error.OutOfMemory if the library could not allocate the object. Use an object from one thread at a time; it may be handed from one thread to another.
Releases the native object. Call it exactly once per object (usually with defer); the handle is invalid afterwards. Objects returned by methods are owned by the caller too and are released the same way.
Wraps a handle obtained from the C API (chilkat.c.CkScMinidriver), taking ownership of it. The struct's handle field goes the other way, for anything the Zig API does not cover.
Errors and memory
Methods that can fail return an error union: a method whose only outcome is success or failure returns Error!void; a method producing a string returns (Error || Allocator.Error)![:0]u8; a method producing an object returns Error!T. chilkat.Error is error{ChilkatFailed}; the reason for a failure is in getLastErrorText, and the object remains usable. Properties never fail, and methods that answer a question (hasMember, isUnlocked, ...) return a plain bool.
String arguments are [:0]const u8 (UTF-8; string literals can be passed as is). String results are copies allocated with the allocator argument and owned by the caller, so they stay valid across later calls on the same object.
const text = sc_minidriver.someMethod(allocator, ...) catch |err| {
const why = try sc_minidriver.getLastErrorText(allocator);
defer allocator.free(why);
std.debug.print("{s}\n", .{why});
return err;
};
defer allocator.free(text);
Properties
Atr
pub fn getAtr(self: ScMinidriver, allocator: Allocator) Allocator.Error![:0]u8
The ATR of the card in the reader. This property is set by the AquireContext method.
topCardName
pub fn getCardName(self: ScMinidriver, allocator: Allocator) Allocator.Error![:0]u8
The name of the card in the reader. This property is set by the AquireContext method.
topDebugLogFilePath
pub fn getDebugLogFilePath(self: ScMinidriver, allocator: Allocator) Allocator.Error![:0]u8
pub fn setDebugLogFilePath(self: ScMinidriver, value: [:0]const u8) void
If set to a file path, this property logs the LastErrorText of each Chilkat method or property call to the specified file. This logging helps identify the context and history of Chilkat calls leading up to any crash or hang, aiding in debugging.
Enabling the VerboseLogging property provides more detailed information. This property is mainly used for debugging rare instances where a Chilkat method call causes a hang or crash, which should generally not happen.
Possible causes of hangs include:
- A timeout property set to 0, indicating an infinite timeout.
- A hang occurring within an event callback in the application code.
- An internal bug in the Chilkat code causing the hang.
LastErrorHtml
pub fn getLastErrorHtml(self: ScMinidriver, allocator: Allocator) Allocator.Error![:0]u8
Provides HTML-formatted information about the last called method or property. If a method call fails or behaves unexpectedly, check this property for details. Note that information is available regardless of the method call's success.
topLastErrorText
pub fn getLastErrorText(self: ScMinidriver, allocator: Allocator) Allocator.Error![:0]u8
Provides plain text information about the last called method or property. If a method call fails or behaves unexpectedly, check this property for details. Note that information is available regardless of the method call's success.
LastErrorXml
pub fn getLastErrorXml(self: ScMinidriver, allocator: Allocator) Allocator.Error![:0]u8
Provides XML-formatted information about the last called method or property. If a method call fails or behaves unexpectedly, check this property for details. Note that information is available regardless of the method call's success.
topLastMethodSuccess
pub fn getLastMethodSuccess(self: ScMinidriver) bool
pub fn setLastMethodSuccess(self: ScMinidriver, value: bool) void
Indicates the success or failure of the most recent method call: true means success, false means failure. This property remains unchanged by property setters or getters. This method is present to address challenges in checking for null or Nothing returns in certain programming languages. Note: This property does not apply to methods that return integer values or to boolean-returning methods where the boolean does not indicate success or failure.
MaxContainers
pub fn getMaxContainers(self: ScMinidriver) i32
The maximum number of key containers available. The 1st key container is at index 0. Each key container can potentially contain one signature key, and one key exchange key.
topRsaPaddingHash
pub fn getRsaPaddingHash(self: ScMinidriver, allocator: Allocator) Allocator.Error![:0]u8
pub fn setRsaPaddingHash(self: ScMinidriver, value: [:0]const u8) void
If an RSA key is used for signing, this is the hash algorithm to used in conjunction with the padding scheme. It can be SHA1, SHA256, SHA384, or SHA512. The default is SHA256.
RsaPaddingScheme
pub fn getRsaPaddingScheme(self: ScMinidriver, allocator: Allocator) Allocator.Error![:0]u8
pub fn setRsaPaddingScheme(self: ScMinidriver, value: [:0]const u8) void
If an RSA key is used for signing, this is the padding scheme to use. It can be PKCS or PSS. The default is PSS.
UncommonOptions
pub fn getUncommonOptions(self: ScMinidriver, allocator: Allocator) Allocator.Error![:0]u8
pub fn setUncommonOptions(self: ScMinidriver, value: [:0]const u8) void
This is a catch-all property to be used for uncommon needs. This property defaults to the empty string and should typically remain empty.
topVerboseLogging
pub fn getVerboseLogging(self: ScMinidriver) bool
pub fn setVerboseLogging(self: ScMinidriver, value: bool) void
If set to true, then the contents of LastErrorText (or LastErrorXml, or LastErrorHtml) may contain more verbose information. The default value is false. Verbose logging should only be used for debugging. The potentially large quantity of logged information may adversely affect peformance.
Version
pub fn getVersion(self: ScMinidriver, allocator: Allocator) Allocator.Error![:0]u8
Methods
AcquireContext
Initializes communication with the card inserted in the given reader. Reader names can be discovered via the SCard.ListReaders or SCard.FindSmartcards methods. If successful, the Atr and CardName properties will be set.
Returns error.ChilkatFailed on failure; getLastErrorText explains why.
CardDeleteFile
Deletes the file specified by dir_name and file_name. dir_name is the name of the directory that contains the file, or the empty string for root.
Returns error.ChilkatFailed on failure; getLastErrorText explains why.
DeleteCert
Deletes a certificate and optionally its associated private key from the smart card. If del_priv_key is true, then the associated private key, if it exists, is also deleted.
Returns error.ChilkatFailed on failure; getLastErrorText explains why.
DeleteContext
This function reverses the effect of AcquireContext and severs the communication between the Base CSP/KSP and the card minidriver. The Atr and CardName properties are cleared.
Returns error.ChilkatFailed on failure; getLastErrorText explains why.
DeleteKeyContainer
Deletes the key container at the given container_index. This deletes both the signature and key exchange keys that may be contained in the specified key container.
Returns error.ChilkatFailed on failure; getLastErrorText explains why.
EnumFiles
Get the list of files in the directory specified by dir_name. Pass the empty string for the root directory. The filenames are returned in st.
Returns error.ChilkatFailed on failure; getLastErrorText explains why.
FindCert
Finds the certificate where the given cert_part equals the part_value. Possible values for cert_part are: subjectDN, subjectDN_withTags, subjectCN, serial, or serial:issuerCN.
The cert is loaded with the certificate if successful.
Note: If successful, the cert will be linked internally with this ScMinidriver session such that certificate can be used for signing on the smart card when used in other Chilkat classes such as XmlDSigGen, Pdf, Crypt2, Mime, MailMan, etc.
Returns error.ChilkatFailed on failure; getLastErrorText explains why.
GenerateKey
Generates a key to be stored in either the signature or key exchange location within a key container. Creates the key container if it does not already exist. Otherwise replaces the key in the key container.
The key_spec can be sig or kex to specify either the signature or key exchange location.
The key_type can be ecc or rsa.
For RSA keys, the key_size is the size of the key in bits, such as 1024, 2048, 4096, etc. (2048 is a typical value.) For ECC keys, the size can be 256, 384, or 521.
The pin_id can be user, or 3 through 7. (It is typically user.)
Returns error.ChilkatFailed on failure; getLastErrorText explains why.
GetCardProperties
Gets all card properties and returns them in json. See the example below.
Returns error.ChilkatFailed on failure; getLastErrorText explains why.
GetCert
Get the certificate at the specified container_index and key_spec. The key_spec can be sig or kex to specify either the signature or key exchange location within the container. The container_index can be -1 to choose the first key container with a certificate. The key_spec can also be any to choose either sig or kex based on which is present, with preference given to sig if both are present.
The cert is loaded with the certificate if successful.
Note: If successful, the cert will be linked internally with this ScMinidriver session such that certificate can be used for signing on the smart card when used in other Chilkat classes such as XmlDSigGen, Pdf, Crypt2, Mime, MailMan, etc.
Returns error.ChilkatFailed on failure; getLastErrorText explains why.
GetContainerKeys
Queries a key container to get the keys that are present. If the signature public key is present, it is returned in sig_key. If the key exchange key is present, it is returned in kex_key.
Returns error.ChilkatFailed on failure; getLastErrorText explains why.
GetCspContainerMap
Returns the contents of the CSP container map file (cmapfile). The information is returned in the json. This gives an overview of what key containers and certificates exist in the smart card from a CSP's point of view. See the example linked below.
Returns error.ChilkatFailed on failure; getLastErrorText explains why.
ImportCert
Imports a certificate with its private key onto the smart card. The cert must have an accessible private key, such as will be the case if the cert was loaded from a .pfx/.p12, or if the cert was loaded from a Windows certificate store where the private key exists (and can be exported from the Windows certificate store).
The container_index is the container index. It can range from 0 to the MaxContainers-1.
The key_spec can be sig or kex to specify either the signature or key exchange location within the container.
The pin_id can be user, or 3 through 7. (It is typically user.)
Returns error.ChilkatFailed on failure; getLastErrorText explains why.
ImportKey
Imports a key to be stored in either the signature or key exchange location within a key container. Creates the key container if it does not already exist. Otherwise replaces the specified key in the key container.
The key_spec can be sig or kex to specify either the signature or key exchange location.
The priv_key is the private key to import.
The ARG5 can be user, or 3 through 7. (It is typically user.)
Returns error.ChilkatFailed on failure; getLastErrorText explains why.
ListCerts
Lists the certs found on the smart card. The cert_part indicates the information to be returned from each certificate. Possible values are: subjectDN, subjectDN_withTags, subjectCN, serial, or serial:issuerCN. The information is returned in st.
Returns error.ChilkatFailed on failure; getLastErrorText explains why.
PinAuthenticate
Performs regular PIN authentication. The pin_id can be user, admin, or 3 through 7. (It is typically user.) The pin is the alphanumeric PIN.
Returns 0 for success. If not successful, the return value indicates the number of attempts remaining before the PIN is locked. (The number of times an incorrect PIN may be presented to the card before the PIN is blocked, and requires the admin to unblock it.) If the PIN is already blocked, the return value is -1. If the method fails for some other reason, such as if a context has not yet been acquired, the return value is -2.
PinAuthenticateHex
The same as PinAutheneticate, but the PIN is passed as a hex string. For example, to pass a PIN of 0x01, 0x02, 0x03, 0x04, pass 01020304.
PinChange
Changes a PIN. The pin_id can be user, admin, or 3 through 7. (It is typically user.) The current_pin is the current alphanumeric PIN. The new_pin is the new PIN.
Returns 0 for success. If not successful, the return value indicates the number of attempts remaining before the PIN is locked. (The number of times an incorrect PIN may be presented to the card before the PIN is blocked, and requires the admin to unblock it.) If the PIN is already blocked, the return value is -1. If the method fails for some other reason, such as if a context has not yet been acquired, the return value is -2.
PinDeauthenticate
Reverses a previous PIN authentication without resetting the card. The pin_id can be user, admin, or 3 through 7. (It is typically user.)
Returns error.ChilkatFailed on failure; getLastErrorText explains why.
ReadFile
Reads the entire file specified by dir_name and file_name into bd. dir_name is the name of the directory that contains the file, or the empty string for root.
Returns error.ChilkatFailed on failure; getLastErrorText explains why.
SignData
Signs the data passed in bd_data. The hash_data_alg can be sha1, sha256, sha384, sha512, or none. If not equal to none, then the hash of the data passed in bd_data is signed.
The container_index specifies the key container. By specifying the key container, you are almost specifying the key. A key container can contain two keys: A signature key, and a key-exchange key. The key_spec indicates which of these two keys to use. key_spec should be set to sig or kex.
Note: The type of signature created, such as RSA or ECC, is determined by the type of key that exists in the key container (specified by container_index and key_spec). If it is an RSA key, additional options can be specified via the RsaPaddingScheme and RsaPaddingHash properties.
If successful, the signature is written to bd_signed_data.
Returns error.ChilkatFailed on failure; getLastErrorText explains why.
WriteFile
Writes the entire file specified by dir_name and file_name. dir_name is the name of the directory that contains the file, or the empty string for root. The entire contents of bd are written to the file on the smart card.
Returns error.ChilkatFailed on failure; getLastErrorText explains why.