Sample code for 30+ languages & platforms
Dart Requires Chilkat v11.0.0+

Create JWK Set Containing Certificates

See more Certificates Examples

Demonstrates how to create a JWK Set containing N certificates.

Chilkat Dart Downloads

Dart
import 'package:chilkat/chilkat.dart';

void main() {
  // This example creates the following JWK Set from two certificates:

  // {
  //   "keys": [
  //     {
  //       "kty": "RSA",
  //       "use": "sig",
  //       "kid": "BB8CeFVqyaGrGNuehJIiL4dfjzw",
  //       "x5t": "BB8CeFVqyaGrGNuehJIiL4dfjzw",
  //       "n": "nYf1jpn7cFdQ...9Iw",
  //       "e": "AQAB",
  //       "x5c": [
  //         "MIIDBTCCAe2...Z+NTZo"
  //       ]
  //     },
  //     {
  //       "kty": "RSA",
  //       "use": "sig",
  //       "kid": "M6pX7RHoraLsprfJeRCjSxuURhc",
  //       "x5t": "M6pX7RHoraLsprfJeRCjSxuURhc",
  //       "n": "xHScZMPo8F...EO4QQ",
  //       "e": "AQAB",
  //       "x5c": [
  //         "MIIC8TCCAdmgA...Vt5432GA=="
  //       ]
  //     }
  //   ]
  // }

  // First get two certificates from files.
  final cert1 = CkCert();
  try {
    cert1.loadFromFile('qa_data/certs/brasil_cert.pem');
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  final cert2 = CkCert();
  try {
    cert2.loadFromFile('qa_data/certs/testCert.cer');
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // We'll need this crypt object re-encode the SHA1 thumbprint from hex to base64.
  final crypt = CkCrypt2();

  final json = CkJsonObject();

  // Let's begin with the 1st cert:
  json.i = 0;
  json.updateString('keys[i].kty', 'RSA');
  json.updateString('keys[i].use', 'sig');

  var hexThumbprint = cert1.sha1Thumbprint;
  var base64Thumbprint = crypt.reEncode(hexThumbprint, 'hex', 'base64');
  json.updateString('keys[i].kid', base64Thumbprint);
  json.updateString('keys[i].x5t', base64Thumbprint);

  // (We're assuming these are RSA certificates)
  // To get the modulus (n) and exponent (e), we need to get the cert's public key and then get its JWK.
  final pubKey = CkPublicKey();
  cert1.getPublicKey(pubKey);

  final pubKeyJwk = CkJsonObject();
  pubKeyJwk.load(pubKey.getJwk());
  json.updateString('keys[i].n', pubKeyJwk.stringOf('n'));
  json.updateString('keys[i].e', pubKeyJwk.stringOf('e'));

  // Now add the entire X.509 certificate 
  json.updateString('keys[i].x5c[0]', cert1.getEncoded());

  // Now do the same for cert2..
  json.i = 1;

  json.updateString('keys[i].kty', 'RSA');
  json.updateString('keys[i].use', 'sig');

  hexThumbprint = cert2.sha1Thumbprint;
  base64Thumbprint = crypt.reEncode(hexThumbprint, 'hex', 'base64');
  json.updateString('keys[i].kid', base64Thumbprint);
  json.updateString('keys[i].x5t', base64Thumbprint);
  cert2.getPublicKey(pubKey);

  pubKeyJwk.load(pubKey.getJwk());
  json.updateString('keys[i].n', pubKeyJwk.stringOf('n'));
  json.updateString('keys[i].e', pubKeyJwk.stringOf('e'));

  // Now add the entire X.509 certificate 
  json.updateString('keys[i].x5c[0]', cert2.getEncoded());

  // Emit the JSON..
  json.emitCompact = false;
  print(json.emit());
}