Sample code for 30+ languages & platforms
Tcl

Get Recipient Certificate Info from Encrypted S/MIME

See more MIME Examples

Demonstrates GetDecryptCertInfo, which examines an encrypted S/MIME entity and writes the recipient-certificate identifiers into a JsonObject. This reveals which certificate(s) the message was encrypted for, so the correct private key can be located before decrypting.

The file paths are relative to the application's current working directory. Absolute paths may also be used. Supply the paths appropriate to your own environment.

Tip: Code to parse the returned JSON can be generated with Chilkat's online tool at https://tools.chilkat.io/jsonParse.

Background. A CMS/PKCS #7 encrypted message carries recipient identifiers (such as issuer and serial number). Inspecting them lets an application determine, without decrypting, which key it needs.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

set mime [new_CkMime]

set success [CkMime_LoadMimeFile $mime "qa_data/encrypted.eml"]
if {$success == 0} then {
    puts [CkMime_lastErrorText $mime]
    delete_CkMime $mime
    exit
}

#  Examine the encrypted entity and write the recipient-certificate identifiers to a JsonObject.
#  This tells you which certificate(s) the message was encrypted for, so you can locate the right
#  private key before attempting to decrypt.
set certInfo [new_CkJsonObject]

set success [CkMime_GetDecryptCertInfo $mime $certInfo]
if {$success == 0} then {
    puts [CkMime_lastErrorText $mime]
    delete_CkMime $mime
    delete_CkJsonObject $certInfo
    exit
}

CkJsonObject_put_EmitCompact $certInfo 0
set json [CkJsonObject_emit $certInfo]
puts "$json"
#  JSON parsing code for this result can be generated at Chilkat's online tool:
#  https://tools.chilkat.io/jsonParse

delete_CkMime $mime
delete_CkJsonObject $certInfo