Sample code for 30+ languages & platforms
Tcl

RSA Encrypt String to Encoded Result and Reverse

See more RSA Examples

Demonstrates how to RSA encrypt a string to a base64 encoded result, and the reverse.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

# The RSA public key is used for encryption, and the private key for decryption.

# The public key's role is to make encryption accessible to anyone while ensuring that
# only the private key holder can decrypt the messages.
# The public key is designed to be widely distributed so anyone can use it to encrypt messages
# intended for the owner of the private key.

# Load our 2048-bit RSA public key.
set pubKey [new_CkPublicKey]

# In all Chilkat methods expecting a path, you pass either absolute or relative paths.
set success [CkPublicKey_LoadFromFile $pubKey "rsaKeys/myTestRsaPublic.pem"]
if {$success == 0} then {
    puts [CkPublicKey_lastErrorText $pubKey]
    delete_CkPublicKey $pubKey
    exit
}

set rsa [new_CkRsa]

# Tell RSA to use the public key.
CkRsa_UsePublicKey $rsa $pubKey

# RSA encryption is for small amounts of data, on the order of 200 bytes or less.
# The maximum number of bytes that can be RSA encrypted depends
# on the RSA key size and padding scheme (OAEP padding vs PKCS#1 v1.5 padding).
# For specific limits, see: RSA Encryption Maximum Number of Bytes

# Encrypt the utf-8 byte representation of the string.
CkRsa_put_Charset $rsa "utf-8"
CkRsa_put_EncodingMode $rsa "base64"

# Be Careful when Using non-us-ascii String Literals in Source Code
set encryptedB64 [CkRsa_encryptStringENC $rsa "Élève français dîne à côté d’un café où l’on sert déjà du gâteau au chocolat et des éclairs délicieux" 0]

# ------------------------------------------------------------------------------------------------------------------------
# Let's decrypt, which requires the matching private key...

# Load the matching 2048-bit RSA private key.
set privKey [new_CkPrivateKey]

set password "secret"
set success [CkPrivateKey_LoadAnyFormatFile $privKey "rsaKeys/myTestRsaPrivate.pem" $password]
if {$success == 0} then {
    puts [CkPrivateKey_lastErrorText $privKey]
    delete_CkPublicKey $pubKey
    delete_CkRsa $rsa
    delete_CkPrivateKey $privKey
    exit
}

# Tell the RSA object to use the private key.
CkRsa_UsePrivateKey $rsa $privKey

# Indicate that after decrypting the resultant decrypted bytes contains the utf-8 byte representation of the text.
CkRsa_put_Charset $rsa "utf-8"
CkRsa_put_EncodingMode $rsa "base64"
set originalText [CkRsa_decryptStringENC $rsa $encryptedB64 1]
if {$success == 0} then {
    puts [CkRsa_lastErrorText $rsa]
    delete_CkPublicKey $pubKey
    delete_CkRsa $rsa
    delete_CkPrivateKey $privKey
    exit
}

puts "Original text = $originalText"
puts "Success."

delete_CkPublicKey $pubKey
delete_CkRsa $rsa
delete_CkPrivateKey $privKey