Sample code for 30+ languages & platforms
Java

MIME S/MIME Encryption Algorithm Properties

See more MIME Examples

Demonstrates the properties that control S/MIME encryption: Pkcs7CryptAlg (the symmetric content-encryption algorithm), Pkcs7KeyLength (the content-encryption key length in bits), OaepPadding (whether RSAES-OAEP key transport is used instead of RSAES-PKCS1-v1_5), and the OAEP hash settings OaepHash and OaepMgfHash. The properties are configured before calling Encrypt.

Background. CMS/PKCS #7 encryption uses a symmetric algorithm to protect the content and an RSA key-transport scheme to protect the symmetric key. The defaults (aes, 128-bit, PKCS1-v1_5 padding) work broadly; these properties tune the algorithms and padding.

Chilkat Java Downloads

Java
import com.chilkatsoft.*;

public class ChilkatExample {

  static {
    try {
        System.loadLibrary("chilkat");
    } catch (UnsatisfiedLinkError e) {
      System.err.println("Native code library failed to load.\n" + e);
      System.exit(1);
    }
  }

  public static void main(String argv[])
  {
    boolean success = false;

    CkMime mime = new CkMime();
    success = mime.SetBodyFromPlainText("This message will be encrypted.");
    if (success == false) {
        System.out.println(mime.lastErrorText());
        return;
        }

    //  Pkcs7CryptAlg is the symmetric content-encryption algorithm.  Supported values are aes, aes-gcm,
    //  des, 3des, and rc2.  The default is aes.
    mime.put_Pkcs7CryptAlg("aes");

    //  Pkcs7KeyLength is the content-encryption key length in bits.  The default is 128.
    mime.put_Pkcs7KeyLength(256);

    //  OaepPadding selects the RSA key-transport padding.  The default is false (RSAES-PKCS1-v1_5).
    //  Set true to use RSAES-OAEP, in which case the OAEP hash settings apply.
    mime.put_OaepPadding(true);
    mime.put_OaepHash("sha256");
    mime.put_OaepMgfHash("sha256");

    //  Load the recipient certificate (public key is sufficient for encrypting).
    CkCert cert = new CkCert();
    success = cert.LoadFromFile("qa_data/recipient.cer");
    if (success == false) {
        System.out.println(cert.lastErrorText());
        return;
        }

    //  Encrypt using the algorithm settings configured above.
    success = mime.Encrypt(cert);
    if (success == false) {
        System.out.println(mime.lastErrorText());
        return;
        }

    System.out.println("Encrypted with " + mime.pkcs7CryptAlg() + " " + mime.get_Pkcs7KeyLength() + "-bit key.");
  }
}