Tcl
Tcl
Encrypt a File to a PKCS7 (CMS) Message
Shows how to encrypt a file into a PKCS7 encrypted message using the recipient's certificate. Public-key encryption requires no private key. However, the recipient's private key is necessary for decryption.Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.
set crypt [new_CkCrypt2]
# Load the recipient's digital certificate.
# We don't need the private key for encryption.
# Only the public key is needed (which is included in a certificate).
set cert1 [new_CkCert]
set success [CkCert_LoadFromFile $cert1 "qa_data/user1/cert_user1.pem"]
# Assume success for the example, but make sure your application checks for success/failure...
CkCrypt2_SetEncryptCert $crypt $cert1
# Indicate that we want PKI encryption (i.e. public-key infrastructure)
# to produce a CMS message (Cryptographic Message Syntax/PKCS7),
# that is be created with RSAES-OAEP padding, SHA256, and AES-256 for the
# bulk encryption.
CkCrypt2_put_CryptAlgorithm $crypt "pki"
CkCrypt2_put_Pkcs7CryptAlg $crypt "aes"
CkCrypt2_put_KeyLength $crypt 256
CkCrypt2_put_OaepHash $crypt "sha256"
CkCrypt2_put_OaepPadding $crypt 1
# Load the file to be encrypted...
set fileData [new_CkBinData]
set success [CkBinData_LoadFile $fileData "qa_data/jpg/penguins.jpg"]
# Your app should check for success/failure..
# Encrypt the data. The contents of the fileData object are replaced with the PKCS7 encrypted message.
set success [CkCrypt2_EncryptBd $crypt $fileData]
if {$success != 1} then {
puts [CkCrypt2_lastErrorText $crypt]
delete_CkCrypt2 $crypt
delete_CkCert $cert1
delete_CkBinData $fileData
exit
}
# Save the PKCS7 encrypted message to a file..
set success [CkBinData_WriteFile $fileData "qa_output/pkcs7_encrypted.p7"]
puts "OK."
delete_CkCrypt2 $crypt
delete_CkCert $cert1
delete_CkBinData $fileData