Sample code for 30+ languages & platforms
Tcl

MIME S/MIME Encryption Algorithm Properties

See more MIME Examples

Demonstrates the properties that control S/MIME encryption: Pkcs7CryptAlg (the symmetric content-encryption algorithm), Pkcs7KeyLength (the content-encryption key length in bits), OaepPadding (whether RSAES-OAEP key transport is used instead of RSAES-PKCS1-v1_5), and the OAEP hash settings OaepHash and OaepMgfHash. The properties are configured before calling Encrypt.

Background. CMS/PKCS #7 encryption uses a symmetric algorithm to protect the content and an RSA key-transport scheme to protect the symmetric key. The defaults (aes, 128-bit, PKCS1-v1_5 padding) work broadly; these properties tune the algorithms and padding.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

set mime [new_CkMime]

set success [CkMime_SetBodyFromPlainText $mime "This message will be encrypted."]
if {$success == 0} then {
    puts [CkMime_lastErrorText $mime]
    delete_CkMime $mime
    exit
}

#  Pkcs7CryptAlg is the symmetric content-encryption algorithm.  Supported values are aes, aes-gcm,
#  des, 3des, and rc2.  The default is aes.
CkMime_put_Pkcs7CryptAlg $mime "aes"

#  Pkcs7KeyLength is the content-encryption key length in bits.  The default is 128.
CkMime_put_Pkcs7KeyLength $mime 256

#  OaepPadding selects the RSA key-transport padding.  The default is 0 (RSAES-PKCS1-v1_5).
#  Set 1 to use RSAES-OAEP, in which case the OAEP hash settings apply.
CkMime_put_OaepPadding $mime 1
CkMime_put_OaepHash $mime "sha256"
CkMime_put_OaepMgfHash $mime "sha256"

#  Load the recipient certificate (public key is sufficient for encrypting).
set cert [new_CkCert]

set success [CkCert_LoadFromFile $cert "qa_data/recipient.cer"]
if {$success == 0} then {
    puts [CkCert_lastErrorText $cert]
    delete_CkMime $mime
    delete_CkCert $cert
    exit
}

#  Encrypt using the algorithm settings configured above.
set success [CkMime_Encrypt $mime $cert]
if {$success == 0} then {
    puts [CkMime_lastErrorText $mime]
    delete_CkMime $mime
    delete_CkCert $cert
    exit
}

puts "Encrypted with [CkMime_pkcs7CryptAlg $mime] [CkMime_get_Pkcs7KeyLength $mime]-bit key."

delete_CkMime $mime
delete_CkCert $cert