Chilkat HOME Android™ Classic ASP C C++ C# Mono C# .NET Core C# C# UWP/WinRT DataFlex Delphi ActiveX Delphi DLL Visual FoxPro Java Lianja MFC Objective-C Perl PHP ActiveX PHP Extension PowerBuilder PowerShell PureBasic CkPython Chilkat2-Python Ruby SQL Server Swift 2 Swift 3,4,5... Tcl Unicode C Unicode C++ Visual Basic 6.0 VB.NET VB.NET UWP/WinRT VBScript Xojo Plugin Node.js Excel Go
(MFC) Create JWK Set Containing CertificatesDemonstrates how to create a JWK Set containing N certificates.
#include <CkCert.h> #include <CkCrypt2.h> #include <CkJsonObject.h> #include <CkPublicKey.h> void ChilkatSample(void) { CkString strOut; // This example creates the following JWK Set from two certificates: // { // "keys": [ // { // "kty": "RSA", // "use": "sig", // "kid": "BB8CeFVqyaGrGNuehJIiL4dfjzw", // "x5t": "BB8CeFVqyaGrGNuehJIiL4dfjzw", // "n": "nYf1jpn7cFdQ...9Iw", // "e": "AQAB", // "x5c": [ // "MIIDBTCCAe2...Z+NTZo" // ] // }, // { // "kty": "RSA", // "use": "sig", // "kid": "M6pX7RHoraLsprfJeRCjSxuURhc", // "x5t": "M6pX7RHoraLsprfJeRCjSxuURhc", // "n": "xHScZMPo8F...EO4QQ", // "e": "AQAB", // "x5c": [ // "MIIC8TCCAdmgA...Vt5432GA==" // ] // } // ] // } // First get two certificates from files. CkCert cert1; bool success = cert1.LoadFromFile("qa_data/certs/brasil_cert.pem"); if (success != true) { strOut.append(cert1.lastErrorText()); strOut.append("\r\n"); SetDlgItemText(IDC_EDIT1,strOut.getUnicode()); return; } CkCert cert2; success = cert2.LoadFromFile("qa_data/certs/testCert.cer"); if (success != true) { strOut.append(cert2.lastErrorText()); strOut.append("\r\n"); SetDlgItemText(IDC_EDIT1,strOut.getUnicode()); return; } // We'll need this crypt object re-encode the SHA1 thumbprint from hex to base64. CkCrypt2 crypt; CkJsonObject json; // Let's begin with the 1st cert: json.put_I(0); json.UpdateString("keys[i].kty","RSA"); json.UpdateString("keys[i].use","sig"); const char *hexThumbprint = cert1.sha1Thumbprint(); const char *base64Thumbprint = crypt.reEncode(hexThumbprint,"hex","base64"); json.UpdateString("keys[i].kid",base64Thumbprint); json.UpdateString("keys[i].x5t",base64Thumbprint); // (We're assuming these are RSA certificates) // To get the modulus (n) and exponent (e), we need to get the cert's public key and then get its JWK. CkPublicKey *pubKey = cert1.ExportPublicKey(); CkJsonObject pubKeyJwk; pubKeyJwk.Load(pubKey->getJwk()); delete pubKey; json.UpdateString("keys[i].n",pubKeyJwk.stringOf("n")); json.UpdateString("keys[i].e",pubKeyJwk.stringOf("e")); // Now add the entire X.509 certificate json.UpdateString("keys[i].x5c[0]",cert1.getEncoded()); // Now do the same for cert2.. json.put_I(1); json.UpdateString("keys[i].kty","RSA"); json.UpdateString("keys[i].use","sig"); hexThumbprint = cert2.sha1Thumbprint(); base64Thumbprint = crypt.reEncode(hexThumbprint,"hex","base64"); json.UpdateString("keys[i].kid",base64Thumbprint); json.UpdateString("keys[i].x5t",base64Thumbprint); pubKey = cert2.ExportPublicKey(); pubKeyJwk.Load(pubKey->getJwk()); delete pubKey; json.UpdateString("keys[i].n",pubKeyJwk.stringOf("n")); json.UpdateString("keys[i].e",pubKeyJwk.stringOf("e")); // Now add the entire X.509 certificate json.UpdateString("keys[i].x5c[0]",cert2.getEncoded()); // Emit the JSON.. json.put_EmitCompact(false); strOut.append(json.emit()); strOut.append("\r\n"); SetDlgItemText(IDC_EDIT1,strOut.getUnicode()); } |
© 2000-2022 Chilkat Software, Inc. All Rights Reserved.