Tcl
Tcl
Encrypt a JWE with a Symmetric Wrapping Key
See more JSON Web Encryption (JWE) Examples
Demonstrates Jwe.SetWrappingKey, which sets the symmetric key-wrapping key for a recipient. The key bytes are supplied in a named encoding such as hex or base64.
Background. AES key wrapping protects the content-encryption key with a shared symmetric key. Both parties must possess the same wrapping key.
Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
set jwe [new_CkJwe]
# Protected header: AES key-wrap with AES-256-GCM content encryption.
set header [new_CkJsonObject]
CkJsonObject_UpdateString $header "alg" "A256KW"
CkJsonObject_UpdateString $header "enc" "A256GCM"
set success [CkJwe_SetProtectedHeader $jwe $header]
if {$success == 0} then {
puts [CkJwe_lastErrorText $jwe]
delete_CkJwe $jwe
delete_CkJsonObject $header
exit
}
# Set the symmetric key-wrapping key for recipient 0. The key bytes are provided in the named
# encoding (here base64). In production, obtain the key from a secure source rather than hard-coding
# it.
set base64Key "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU="
set success [CkJwe_SetWrappingKey $jwe 0 $base64Key "base64"]
if {$success == 0} then {
puts [CkJwe_lastErrorText $jwe]
delete_CkJwe $jwe
delete_CkJsonObject $header
exit
}
set jweCompact [CkJwe_encrypt $jwe "This is the secret content." "utf-8"]
if {[CkJwe_get_LastMethodSuccess $jwe] == 0} then {
puts [CkJwe_lastErrorText $jwe]
delete_CkJwe $jwe
delete_CkJsonObject $header
exit
}
puts "$jweCompact"
delete_CkJwe $jwe
delete_CkJsonObject $header