Tcl
Tcl
Encrypt Binary Content to a JWE
See more JSON Web Encryption (JWE) Examples
Demonstrates Jwe.EncryptBd, which encrypts binary content held in a BinData and writes the resulting JWE into a StringBuilder.
Background. JWE (JSON Web Encryption) protects content with a content-encryption algorithm (the header
enc value) while the content-encryption key is managed by the key-management algorithm (the header alg value). This example uses AES key wrapping with a symmetric wrapping key.Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
set jwe [new_CkJwe]
# Set the JWE protected header, specifying the key-management algorithm (alg) and the content-
# encryption algorithm (enc).
set header [new_CkJsonObject]
CkJsonObject_UpdateString $header "alg" "A256KW"
CkJsonObject_UpdateString $header "enc" "A256GCM"
set success [CkJwe_SetProtectedHeader $jwe $header]
if {$success == 0} then {
puts [CkJwe_lastErrorText $jwe]
delete_CkJwe $jwe
delete_CkJsonObject $header
exit
}
# The 256-bit key-wrapping key (base64) for recipient index 0. In production, obtain the key
# from a secure source rather than hard-coding it.
set base64Key "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU="
set success [CkJwe_SetWrappingKey $jwe 0 $base64Key "base64"]
if {$success == 0} then {
puts [CkJwe_lastErrorText $jwe]
delete_CkJwe $jwe
delete_CkJsonObject $header
exit
}
# Encrypt binary content held in a BinData, writing the resulting JWE into a StringBuilder.
set bdContent [new_CkBinData]
CkBinData_AppendString $bdContent "Binary content to encrypt." "utf-8"
set sbJwe [new_CkStringBuilder]
set success [CkJwe_EncryptBd $jwe $bdContent $sbJwe]
if {$success == 0} then {
puts [CkJwe_lastErrorText $jwe]
delete_CkJwe $jwe
delete_CkJsonObject $header
delete_CkBinData $bdContent
delete_CkStringBuilder $sbJwe
exit
}
puts [CkStringBuilder_getAsString $sbJwe]
delete_CkJwe $jwe
delete_CkJsonObject $header
delete_CkBinData $bdContent
delete_CkStringBuilder $sbJwe