Sample code for 30+ languages & platforms
Tcl

Add a Detached Signature with a Separate Private Key

See more MIME Examples

Demonstrates the Chilkat Mime.AddDetachedSignaturePk method, which creates a detached signature using a signer certificate and its separately supplied private key. The first argument is the Cert and the second is the PrivateKey.

Note: The file paths are relative to the application's current working directory. Absolute paths may also be used. Supply the paths appropriate to your own environment.

Background: Sometimes the certificate and its private key live apart — a .cer alongside a PEM key file, for instance — rather than bundled in a single PFX. This method pairs them explicitly for signing, whereas AddDetachedSignature expects a Cert that already provides its key. The result is the same multipart/signed message.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

set mime [new_CkMime]

set success [CkMime_SetBodyFromPlainText $mime "This message will be signed."]
if {$success == 0} then {
    puts [CkMime_lastErrorText $mime]
    delete_CkMime $mime
    exit
}

#  Load the certificate and its private key separately.
set cert [new_CkCert]

set success [CkCert_LoadFromFile $cert "qa_data/signer.cer"]
if {$success == 0} then {
    puts [CkCert_lastErrorText $cert]
    delete_CkMime $mime
    delete_CkCert $cert
    exit
}

set privKey [new_CkPrivateKey]

set success [CkPrivateKey_LoadPemFile $privKey "qa_data/signer_privkey.pem"]
if {$success == 0} then {
    puts [CkPrivateKey_lastErrorText $privKey]
    delete_CkMime $mime
    delete_CkCert $cert
    delete_CkPrivateKey $privKey
    exit
}

#  Create a detached signature when the certificate and private key are supplied separately.  The
#  1st argument is the signer certificate and the 2nd is its private key.
set success [CkMime_AddDetachedSignaturePk $mime $cert $privKey]
if {$success == 0} then {
    puts [CkMime_lastErrorText $mime]
    delete_CkMime $mime
    delete_CkCert $cert
    delete_CkPrivateKey $privKey
    exit
}

set success [CkMime_SaveMime $mime "qa_output/signed.eml"]
if {$success == 0} then {
    puts [CkMime_lastErrorText $mime]
    delete_CkMime $mime
    delete_CkCert $cert
    delete_CkPrivateKey $privKey
    exit
}

puts "Detached signature added."

delete_CkMime $mime
delete_CkCert $cert
delete_CkPrivateKey $privKey