Sample code for 30+ languages & platforms
Zig Requires Chilkat v11.0.0+

Create JWK Set Containing Certificates

See more Certificates Examples

Demonstrates how to create a JWK Set containing N certificates.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example creates the following JWK Set from two certificates:

    // {
    //   "keys": [
    //     {
    //       "kty": "RSA",
    //       "use": "sig",
    //       "kid": "BB8CeFVqyaGrGNuehJIiL4dfjzw",
    //       "x5t": "BB8CeFVqyaGrGNuehJIiL4dfjzw",
    //       "n": "nYf1jpn7cFdQ...9Iw",
    //       "e": "AQAB",
    //       "x5c": [
    //         "MIIDBTCCAe2...Z+NTZo"
    //       ]
    //     },
    //     {
    //       "kty": "RSA",
    //       "use": "sig",
    //       "kid": "M6pX7RHoraLsprfJeRCjSxuURhc",
    //       "x5t": "M6pX7RHoraLsprfJeRCjSxuURhc",
    //       "n": "xHScZMPo8F...EO4QQ",
    //       "e": "AQAB",
    //       "x5c": [
    //         "MIIC8TCCAdmgA...Vt5432GA=="
    //       ]
    //     }
    //   ]
    // }

    // First get two certificates from files.
    const cert1 = try chilkat.Cert.init();
    defer cert1.deinit();
    cert1.loadFromFile("qa_data/certs/brasil_cert.pem") catch {
        std.debug.print("{s}\n", .{try cert1.getLastErrorText(alloc)});
        return;
    };

    const cert2 = try chilkat.Cert.init();
    defer cert2.deinit();
    cert2.loadFromFile("qa_data/certs/testCert.cer") catch {
        std.debug.print("{s}\n", .{try cert2.getLastErrorText(alloc)});
        return;
    };

    // We'll need this crypt object re-encode the SHA1 thumbprint from hex to base64.
    const crypt = try chilkat.Crypt2.init();
    defer crypt.deinit();

    const json = try chilkat.JsonObject.init();
    defer json.deinit();

    // Let's begin with the 1st cert:
    json.setI(0);
    json.updateString("keys[i].kty", "RSA") catch {};
    json.updateString("keys[i].use", "sig") catch {};

    var hex_thumbprint: [:0]const u8 = try cert1.getSha1Thumbprint(alloc);
    var base64_thumbprint: [:0]const u8 = try crypt.reEncode(alloc, hex_thumbprint, "hex", "base64");
    json.updateString("keys[i].kid", base64_thumbprint) catch {};
    json.updateString("keys[i].x5t", base64_thumbprint) catch {};

    // (We're assuming these are RSA certificates)
    // To get the modulus (n) and exponent (e), we need to get the cert's public key and then get its JWK.
    const pub_key = try chilkat.PublicKey.init();
    defer pub_key.deinit();
    cert1.getPublicKey(pub_key) catch {};

    const pub_key_jwk = try chilkat.JsonObject.init();
    defer pub_key_jwk.deinit();
    pub_key_jwk.load(try pub_key.getJwk(alloc)) catch {};
    json.updateString("keys[i].n", try pub_key_jwk.stringOf(alloc, "n")) catch {};
    json.updateString("keys[i].e", try pub_key_jwk.stringOf(alloc, "e")) catch {};

    // Now add the entire X.509 certificate
    json.updateString("keys[i].x5c[0]", try cert1.getEncoded(alloc)) catch {};

    // Now do the same for cert2..
    json.setI(1);

    json.updateString("keys[i].kty", "RSA") catch {};
    json.updateString("keys[i].use", "sig") catch {};

    hex_thumbprint = try cert2.getSha1Thumbprint(alloc);
    base64_thumbprint = try crypt.reEncode(alloc, hex_thumbprint, "hex", "base64");
    json.updateString("keys[i].kid", base64_thumbprint) catch {};
    json.updateString("keys[i].x5t", base64_thumbprint) catch {};
    cert2.getPublicKey(pub_key) catch {};

    pub_key_jwk.load(try pub_key.getJwk(alloc)) catch {};
    json.updateString("keys[i].n", try pub_key_jwk.stringOf(alloc, "n")) catch {};
    json.updateString("keys[i].e", try pub_key_jwk.stringOf(alloc, "e")) catch {};

    // Now add the entire X.509 certificate
    json.updateString("keys[i].x5c[0]", try cert2.getEncoded(alloc)) catch {};

    // Emit the JSON..
    json.setEmitCompact(false);
    std.debug.print("{s}\n", .{try json.emit(alloc)});
}