Sample code for 30+ languages & platforms
PureBasic

Encrypt a File to a PKCS7 (CMS) Message

Shows how to encrypt a file into a PKCS7 encrypted message using the recipient's certificate. Public-key encryption requires no private key. However, the recipient's private key is necessary for decryption.

Chilkat PureBasic Downloads

PureBasic
IncludeFile "CkBinData.pb"
IncludeFile "CkCert.pb"
IncludeFile "CkCrypt2.pb"

Procedure ChilkatExample()

    success.i = 0

    ; This example requires the Chilkat API to have been previously unlocked.
    ; See Global Unlock Sample for sample code.

    crypt.i = CkCrypt2::ckCreate()
    If crypt.i = 0
        Debug "Failed to create object."
        ProcedureReturn
    EndIf

    ; Load the recipient's digital certificate. 
    ; We don't need the private key for encryption.
    ; Only the public key is needed (which is included in a certificate).
    cert1.i = CkCert::ckCreate()
    If cert1.i = 0
        Debug "Failed to create object."
        ProcedureReturn
    EndIf

    success = CkCert::ckLoadFromFile(cert1,"qa_data/user1/cert_user1.pem")
    ; Assume success for the example, but make sure your application checks for success/failure...
    CkCrypt2::ckSetEncryptCert(crypt,cert1)

    ; Indicate that we want PKI encryption (i.e. public-key infrastructure)
    ; to produce a CMS message (Cryptographic Message Syntax/PKCS7),
    ; that is be created with RSAES-OAEP padding, SHA256, and AES-256 for the
    ; bulk encryption.
    CkCrypt2::setCkCryptAlgorithm(crypt, "pki")
    CkCrypt2::setCkPkcs7CryptAlg(crypt, "aes")
    CkCrypt2::setCkKeyLength(crypt, 256)
    CkCrypt2::setCkOaepHash(crypt, "sha256")
    CkCrypt2::setCkOaepPadding(crypt, 1)

    ; Load the file to be encrypted...
    fileData.i = CkBinData::ckCreate()
    If fileData.i = 0
        Debug "Failed to create object."
        ProcedureReturn
    EndIf

    success = CkBinData::ckLoadFile(fileData,"qa_data/jpg/penguins.jpg")
    ; Your app should check for success/failure..

    ; Encrypt the data.  The contents of the fileData object are replaced with the PKCS7 encrypted message.
    success = CkCrypt2::ckEncryptBd(crypt,fileData)
    If success <> 1
        Debug CkCrypt2::ckLastErrorText(crypt)
        CkCrypt2::ckDispose(crypt)
        CkCert::ckDispose(cert1)
        CkBinData::ckDispose(fileData)
        ProcedureReturn
    EndIf

    ; Save the PKCS7 encrypted message to a file..
    success = CkBinData::ckWriteFile(fileData,"qa_output/pkcs7_encrypted.p7")

    Debug "OK."


    CkCrypt2::ckDispose(crypt)
    CkCert::ckDispose(cert1)
    CkBinData::ckDispose(fileData)


    ProcedureReturn
EndProcedure