Sample code for 30+ languages & platforms
Dart

Create JCEKS Containing Secret Keys

See more Java KeyStore (JKS) Examples

Demonstrates how to create a JCEKS keystore file containing symmetric secret keys (for AES, Blowfish, HMAC SHA25, ChaCha20, etc.)

This example requires Chilkat v9.5.0.66 or greater.

Chilkat Dart Downloads

Dart
import 'package:chilkat/chilkat.dart';

void main() {
  // IMPORTANT: This example requires Chilkat v9.5.0.66 or greater.

  // This example requires the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  final jceks = CkJavaKeyStore();

  // We'll need a pseudo-random number generator (PRNG) to generate symmetric keys.
  final prng = CkPrng();

  // Generate some keys..

  // 128-bit AES key (16 bytes)
  final aesKey = prng.genRandom(16, 'base64');

  // 256-bit Blowfish key (32 bytes)
  final blowfishKey = prng.genRandom(32, 'base64');

  // HMAC SHA256 key
  // (An HMAC key can be anything, and any length. We'll use the following string:
  final hmacKey = 'This is my HMAC key';

  // ChaCha20 256-bit
  final chachaKey = prng.genRandom(32, 'base64');

  // Add each secret key to the JCEKS
  final encoding = 'base64';
  final password = 'secret';
  jceks.addSecretKey(aesKey, encoding, 'AES', 'my aes key', password);
  jceks.addSecretKey(blowfishKey, encoding, 'BLOWFISH', 'my blowfish key', password);
  // For HMAC, we're using the us-ascii bytes for the key..
  jceks.addSecretKey(hmacKey, 'ascii', 'HMAC_SHA256', 'my hmac key', password);
  jceks.addSecretKey(chachaKey, encoding, 'CHACHA', 'my chacha20 key', password);

  final filePassword = 'password';
  // Write the JCEKs to a file.
  try {
    jceks.toFile(filePassword, 'qa_output/secretKeys.jceks');
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // We can also emit as a JWK Set..
  final sbJson = CkStringBuilder();
  try {
    jceks.toJwkSet('secret', sbJson);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Emit the JSON in pretty-printed (indented) form:
  final json = CkJsonObject();
  json.loadSb(sbJson);
  json.emitCompact = false;
  print(json.emit());

  // Output is:

  // { 
  //   "keys": [
  //     { 
  //       "kty": "oct",
  //       "alg": "AES",
  //       "k": "vHekQQB0Gc1NvppapUTW2g",
  //       "kid": "my aes key"
  //     },
  //     { 
  //       "kty": "oct",
  //       "alg": "BLOWFISH",
  //       "k": "qHsdXaJsXicVCZbK8l8hJQpYOa0GkiO9gsRK9WLtht8",
  //       "kid": "my blowfish key"
  //     },
  //     { 
  //       "kty": "oct",
  //       "alg": "HMAC_SHA256",
  //       "k": "VGhpcyBpcyBteSBITUFDIGtleQ",
  //       "kid": "my hmac key"
  //     },
  //     { 
  //       "kty": "oct",
  //       "alg": "CHACHA",
  //       "k": "yNv832U43C9BcWvaQAH2_rG-GwfmpgT5JBRllWGQY1o",
  //       "kid": "my chacha20 key"
  //     }
  //   ]
  // }
  // 
}