Sample code for 30+ languages & platforms
CkPython

MIME S/MIME Encryption Algorithm Properties

See more MIME Examples

Demonstrates the properties that control S/MIME encryption: Pkcs7CryptAlg (the symmetric content-encryption algorithm), Pkcs7KeyLength (the content-encryption key length in bits), OaepPadding (whether RSAES-OAEP key transport is used instead of RSAES-PKCS1-v1_5), and the OAEP hash settings OaepHash and OaepMgfHash. The properties are configured before calling Encrypt.

Background. CMS/PKCS #7 encryption uses a symmetric algorithm to protect the content and an RSA key-transport scheme to protect the symmetric key. The defaults (aes, 128-bit, PKCS1-v1_5 padding) work broadly; these properties tune the algorithms and padding.

Chilkat CkPython Downloads

CkPython
import sys
import chilkat

success = False

mime = chilkat.CkMime()
success = mime.SetBodyFromPlainText("This message will be encrypted.")
if (success == False):
    print(mime.lastErrorText())
    sys.exit()

#  Pkcs7CryptAlg is the symmetric content-encryption algorithm.  Supported values are aes, aes-gcm,
#  des, 3des, and rc2.  The default is aes.
mime.put_Pkcs7CryptAlg("aes")

#  Pkcs7KeyLength is the content-encryption key length in bits.  The default is 128.
mime.put_Pkcs7KeyLength(256)

#  OaepPadding selects the RSA key-transport padding.  The default is False (RSAES-PKCS1-v1_5).
#  Set True to use RSAES-OAEP, in which case the OAEP hash settings apply.
mime.put_OaepPadding(True)
mime.put_OaepHash("sha256")
mime.put_OaepMgfHash("sha256")

#  Load the recipient certificate (public key is sufficient for encrypting).
cert = chilkat.CkCert()
success = cert.LoadFromFile("qa_data/recipient.cer")
if (success == False):
    print(cert.lastErrorText())
    sys.exit()

#  Encrypt using the algorithm settings configured above.
success = mime.Encrypt(cert)
if (success == False):
    print(mime.lastErrorText())
    sys.exit()

print("Encrypted with " + mime.pkcs7CryptAlg() + " " + str(mime.get_Pkcs7KeyLength()) + "-bit key.")