Sample code for 30+ languages & platforms
Zig

Create PKCS7 (CMS) EnvelopedData

Encrypt some data to a recipient by creating a PKCS7 (CMS) EnvelopedData structure. The data will be encrypted using a symmetric content-encryption algorithm (e.g., AES), and the randomly generated symmetric key will be encrypted using the recipient’s RSA public key extracted from their X.509 certificate.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    var success: bool = false;

    const crypt = try chilkat.Crypt2.init();
    defer crypt.deinit();

    // Specify the encryption to be used.
    // "pki" indicates "Public Key Infrastructure" and will create a PKCS7 encrypted (enveloped-data) message.
    crypt.setCryptAlgorithm("pki");
    crypt.setPkcs7CryptAlg("aes");
    crypt.setKeyLength(256);
    crypt.setOaepHash("sha256");
    crypt.setOaepPadding(true);

    const cert = try chilkat.Cert.init();
    defer cert.deinit();

    // Use a certificate found in the Windows certificate store.
    success = if (cert.loadByCommonName("My Certificate")) true else |_| false;
    if (!success) {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    }

    // Tell the crypt object to use the certificate.
    crypt.setEncryptCert(cert) catch {};

    const to_be_encrypted = "This string is to be encrypted.";

    // Get the result in multi-line BASE64 MIME format.
    crypt.setEncodingMode("base64_mime");
    crypt.setCharset("utf-8");

    const result = try crypt.encryptStringENC(alloc, to_be_encrypted);
    if (!success) {
        std.debug.print("{s}\n", .{try crypt.getLastErrorText(alloc)});
        return;
    }

    // -------------------------------------------------------------------------
    // See the following example to decrypt what was created in this example
    // Decrypt PKCS7 (CMS) EnvelopedData
    // -------------------------------------------------------------------------

    std.debug.print("{s}\n", .{result});

    // Sample output:

    // MIICSgYJKoZIhvcNAQcDoIICOzCCAjcCAQAxggHiMIIB3gIBADCBljCBgTELMAkGA1UEBhMCSVQx
    // EDAOBgNVBAgMB0JlcmdhbW8xGTAXBgNVBAcMEFBvbnRlIFNhbiBQaWV0cm8xFzAVBgNVBAoMDkFj
    // dGFsaXMgUy5wLkEuMSwwKgYDVQQDDCNBY3RhbGlzIENsaWVudCBBdXRoZW50aWNhdGlvbiBDQSBH
    // MwIQPCWvkSv8oQ7xRmEHJ6TzEDA8BgkqhkiG9w0BAQcwL6APMA0GCWCGSAFlAwQCAQUAoRwwGgYJ
    // KoZIhvcNAQEIMA0GCWCGSAFlAwQCAQUABIIBAKqHAPQNSsQoX7B2NH7QyEOWQRsSVs8oCHXmy8f4
    // MVZD2er3bvYUCIomxpwbLEAl14qjUIMynahooYGgqip7+4FqL301G+BVjZVfEhHWj+VI1dAWnWuL
    // VHlvc/pbQNBWqV8rKVJsNIsuAZkdj4WSwLVKxYkYX43B8fh/g71XN2DTJu7Z/824v48KBmgpQBOT
    // 2q7IcDGxNPAFN2p6eavIVGn2LvhEbf/Fszyj+GR5tMcnQP1BOLJ3s3JzUBbvj8hcZrF1Vhl9HnTU
    // YQx8G/KdW1mR+Wlhl3BWoK0LYKRTbnTx2BXOs0CY1SXOAdhKr01ZYjA+xW4nGzY0lfXS9QZjh9gw
    // TAYJKoZIhvcNAQcBMB0GCWCGSAFlAwQBKgQQw0xTbfmnt0zjWHo5SaQIp4AgxTVY9E/Ncqy6t+RM
    // 8y4c3Av62/wB8IpPUEmtM2OeuZo=
}