Sample code for 30+ languages & platforms
Zig

Create JCEKS Containing Secret Keys

See more Java KeyStore (JKS) Examples

Demonstrates how to create a JCEKS keystore file containing symmetric secret keys (for AES, Blowfish, HMAC SHA25, ChaCha20, etc.)

This example requires Chilkat v9.5.0.66 or greater.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // IMPORTANT: This example requires Chilkat v9.5.0.66 or greater.

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    const jceks = try chilkat.JavaKeyStore.init();
    defer jceks.deinit();

    // We'll need a pseudo-random number generator (PRNG) to generate symmetric keys.
    const prng = try chilkat.Prng.init();
    defer prng.deinit();

    // Generate some keys..

    // 128-bit AES key (16 bytes)
    const aes_key = try prng.genRandom(alloc, 16, "base64");

    // 256-bit Blowfish key (32 bytes)
    const blowfish_key = try prng.genRandom(alloc, 32, "base64");

    // HMAC SHA256 key
    // (An HMAC key can be anything, and any length. We'll use the following string:
    const hmac_key = "This is my HMAC key";

    // ChaCha20 256-bit
    const chacha_key = try prng.genRandom(alloc, 32, "base64");

    // Add each secret key to the JCEKS
    const encoding = "base64";
    const password = "secret";
    jceks.addSecretKey(aes_key, encoding, "AES", "my aes key", password) catch {};
    jceks.addSecretKey(blowfish_key, encoding, "BLOWFISH", "my blowfish key", password) catch {};
    // For HMAC, we're using the us-ascii bytes for the key..
    jceks.addSecretKey(hmac_key, "ascii", "HMAC_SHA256", "my hmac key", password) catch {};
    jceks.addSecretKey(chacha_key, encoding, "CHACHA", "my chacha20 key", password) catch {};

    const file_password = "password";
    // Write the JCEKs to a file.
    jceks.toFile(file_password, "qa_output/secretKeys.jceks") catch {
        std.debug.print("{s}\n", .{try jceks.getLastErrorText(alloc)});
        return;
    };

    // We can also emit as a JWK Set..
    const sb_json = try chilkat.StringBuilder.init();
    defer sb_json.deinit();
    jceks.toJwkSet("secret", sb_json) catch {
        std.debug.print("{s}\n", .{try jceks.getLastErrorText(alloc)});
        return;
    };

    // Emit the JSON in pretty-printed (indented) form:
    const json = try chilkat.JsonObject.init();
    defer json.deinit();
    json.loadSb(sb_json) catch {};
    json.setEmitCompact(false);
    std.debug.print("{s}\n", .{try json.emit(alloc)});

    // Output is:

    // {
    //   "keys": [
    //     {
    //       "kty": "oct",
    //       "alg": "AES",
    //       "k": "vHekQQB0Gc1NvppapUTW2g",
    //       "kid": "my aes key"
    //     },
    //     {
    //       "kty": "oct",
    //       "alg": "BLOWFISH",
    //       "k": "qHsdXaJsXicVCZbK8l8hJQpYOa0GkiO9gsRK9WLtht8",
    //       "kid": "my blowfish key"
    //     },
    //     {
    //       "kty": "oct",
    //       "alg": "HMAC_SHA256",
    //       "k": "VGhpcyBpcyBteSBITUFDIGtleQ",
    //       "kid": "my hmac key"
    //     },
    //     {
    //       "kty": "oct",
    //       "alg": "CHACHA",
    //       "k": "yNv832U43C9BcWvaQAH2_rG-GwfmpgT5JBRllWGQY1o",
    //       "kid": "my chacha20 key"
    //     }
    //   ]
    // }
    //
}