Sample code for 30+ languages & platforms
Zig

Encrypt/Decrypt using PFX to produce -----BEGIN PKCS7----- ... -----END PKCS7-----

See more Encryption Examples

First we encrypt using a certificate + public key to produce output such as:
-----BEGIN PKCS7-----
MIIHPwYJKoZIhvcNAQcEoIIHMDCCBywC ...
...
...
-----END PKCS7-----
Then we decrypt using the cert + private key.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    var success: bool = false;

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    const crypt = try chilkat.Crypt2.init();
    defer crypt.deinit();

    // Specify the encryption to be used.
    // "pki" indicates "Public Key Infrastructure" and will create a PKCS7 encrypted (enveloped) message.
    crypt.setCryptAlgorithm("pki");
    crypt.setPkcs7CryptAlg("aes");
    crypt.setKeyLength(128);
    crypt.setOaepHash("sha256");
    crypt.setOaepPadding(true);

    // A certificate is needed as the encryption key.
    // Althought the PFX contains the associated private key, we don't need it for encryption.
    // (A certificate usually contains the public key by default.)
    const cert = try chilkat.Cert.init();
    defer cert.deinit();
    success = if (cert.loadPfxFile("qa_data/pfx/cert_test123.pfx", "test123")) true else |_| false;
    if (!success) {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    }

    // Tell the crypt object to use the certificate.
    crypt.setEncryptCert(cert) catch {};

    const to_be_encrypted = "This string is to be encrypted.";

    // Get the result in multi-line BASE64 MIME format.
    crypt.setEncodingMode("base64_mime");

    const encrypted_str = try crypt.encryptStringENC(alloc, to_be_encrypted);
    if (!success) {
        std.debug.print("{s}\n", .{try crypt.getLastErrorText(alloc)});
        return;
    }

    // Make a "-----BEGIN PKCS7-----" ... "-----END PKCS7-----" sandwich...
    const sb = try chilkat.StringBuilder.init();
    defer sb.deinit();
    sb.appendLine("-----BEGIN PKCS7-----", true) catch {};
    sb.append(encrypted_str) catch {};
    sb.appendLine("-----END PKCS7-----", true) catch {};

    const out_str = try sb.getAsString(alloc);

    std.debug.print("{s}\n", .{out_str});

    // Sample output:

    // -----BEGIN PKCS7-----
    // MIICXAYJKoZIhvcNAQcDoIICTTCCAkkCAQAxggH0MIIB8AIBADCBrDCBlzELMAkGA1UEBhMCR0Ix
    // GzAZBgNVBAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4GA1UEBxMHU2FsZm9yZDEaMBgGA1UEChMR
    // Q09NT0RPIENBIExpbWl0ZWQxPTA7BgNVBAMTNENPTU9ETyBSU0EgQ2xpZW50IEF1dGhlbnRpY2F0
    // aW9uIGFuZCBTZWN1cmUgRW1haWwgQ0ECEB6M1ZwZdZU7LrAIdurulmUwOAYJKoZIhvcNAQEHMCug
    // DzANBglghkgBZQMEAgEFAKEYMBYGCSqGSIb3DQEBCDAJBgUrDgMCGgUABIIBAK/BZG/iXJ8az7zL
    // 8EQ77mc+oDPQ4w1hyytK2ip4djkPVvTfYhcoDQ+G/DBU+urJfrVBi5H9gmpXwYyfKlyUxBVRVEJl
    // V/V5QQi4JmNTFbmgWh5tp9zDS98l6A2Va4Zs0Wy/owGLfvwitlxd1dsfVAV2hmBYS24BMpNcty5/
    // 0atcKYmSou13G78ztTKdMy1tECgZy8kerMsPdDQbSxEZkT3KpQ8C5uEQqYF3bIVaeZzha/Ywieh/
    // tvO0T4aAmeJufwkNdVECmU7kuhnNaVPXknFl7jeibTl6zA/VcJKBKcIYT9FRC7KjdooI8q+jtQ/V
    // k6RP4POaowkFg1QWRPEWeqIwTAYJKoZIhvcNAQcBMB0GCWCGSAFlAwQBAgQQEEFQduqeJqXQXzy4
    // JpkoDoAgdldJDB9zEkpMpgr5/fR2iLvh5kC6BPfhOYjsawBY4Ok=
    // -----END PKCS7-----

    // ----------------------------------------------------------------------------------------
    // Let's Decrypt the above string.

    // Start with what was produced above..
    sb.clear();
    const b_crlf = true;
    sb.appendLine("-----BEGIN PKCS7-----", b_crlf) catch {};
    sb.appendLine("MIICXAYJKoZIhvcNAQcDoIICTTCCAkkCAQAxggH0MIIB8AIBADCBrDCBlzELMAkGA1UEBhMCR0Ix", b_crlf) catch {};
    sb.appendLine("GzAZBgNVBAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4GA1UEBxMHU2FsZm9yZDEaMBgGA1UEChMR", b_crlf) catch {};
    sb.appendLine("Q09NT0RPIENBIExpbWl0ZWQxPTA7BgNVBAMTNENPTU9ETyBSU0EgQ2xpZW50IEF1dGhlbnRpY2F0", b_crlf) catch {};
    sb.appendLine("aW9uIGFuZCBTZWN1cmUgRW1haWwgQ0ECEB6M1ZwZdZU7LrAIdurulmUwOAYJKoZIhvcNAQEHMCug", b_crlf) catch {};
    sb.appendLine("DzANBglghkgBZQMEAgEFAKEYMBYGCSqGSIb3DQEBCDAJBgUrDgMCGgUABIIBAK/BZG/iXJ8az7zL", b_crlf) catch {};
    sb.appendLine("8EQ77mc+oDPQ4w1hyytK2ip4djkPVvTfYhcoDQ+G/DBU+urJfrVBi5H9gmpXwYyfKlyUxBVRVEJl", b_crlf) catch {};
    sb.appendLine("V/V5QQi4JmNTFbmgWh5tp9zDS98l6A2Va4Zs0Wy/owGLfvwitlxd1dsfVAV2hmBYS24BMpNcty5/", b_crlf) catch {};
    sb.appendLine("0atcKYmSou13G78ztTKdMy1tECgZy8kerMsPdDQbSxEZkT3KpQ8C5uEQqYF3bIVaeZzha/Ywieh/", b_crlf) catch {};
    sb.appendLine("tvO0T4aAmeJufwkNdVECmU7kuhnNaVPXknFl7jeibTl6zA/VcJKBKcIYT9FRC7KjdooI8q+jtQ/V", b_crlf) catch {};
    sb.appendLine("k6RP4POaowkFg1QWRPEWeqIwTAYJKoZIhvcNAQcBMB0GCWCGSAFlAwQBAgQQEEFQduqeJqXQXzy4", b_crlf) catch {};
    sb.appendLine("JpkoDoAgdldJDB9zEkpMpgr5/fR2iLvh5kC6BPfhOYjsawBY4Ok=", b_crlf) catch {};
    sb.appendLine("-----END PKCS7-----", b_crlf) catch {};

    const decrypt = try chilkat.Crypt2.init();
    defer decrypt.deinit();
    decrypt.setCryptAlgorithm("pki");

    // Use the same cert + private key from the PFX above.
    // For decryption, we need the private key.  Given that the certificate was loaded from a PFX,
    // we should already have it.
    success = if (decrypt.setDecryptCert(cert)) true else |_| false;

    decrypt.setEncodingMode("base64");
    const decrypted_text = try decrypt.decryptStringENC(alloc, try sb.getBetween(alloc, "-----BEGIN PKCS7-----", "-----END PKCS7-----"));

    std.debug.print("{s}\n", .{decrypted_text});
}