Sample code for 30+ languages & platforms
Rust Requires Chilkat v11.0.0+

Get ETK Public Key (api-acpt.ehealth.fgov.be)

See more Belgian eHealth Platform Examples

The following URL returns JSON, which contains a PKCS7 signed data:
https://api-acpt.ehealth.fgov.be/etee/v1/etks?identifier=12345678901&type=SSIN

This example extracts the signed data, validates it, and then extracts the public key from the certificate (obtained from signed content in the PKCS7)

Note: The URL above uses "12345678901" which is not valid. You should replace it with a valid number.

Chilkat Rust Downloads

Rust

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

let http = chilkat::Http::new();

let Ok(json_str) = http.quick_get_str("https://api-acpt.ehealth.fgov.be/etee/v1/etks?identifier=12345678901&type=SSIN") else {
    println!("{}", http.last_error_text());
    return;
};

println!("{}", json_str);

// The JSON contains something like this:

// [
//     {
//         "key": {
//             "applicationIdentifier": "",
//             "ssin": "12345678901"
//         },
//         "value": "MIAGCSq....AAAAAAAA=="
//     }
// ]

// Note: The above is a JSON array (not a JSON object)
// It should be loaded into a Chilkat JSON array.
let jarr = chilkat::JsonArray::new();
if jarr.load(&json_str).is_err() {
    println!("Failed to load JSON.");
    return;
}

let json = jarr.object_at(0).unwrap();
let bd_pkcs7 = chilkat::BinData::new();
let _ = bd_pkcs7.append_encoded(&json.string_of("value").unwrap_or_default(), "base64");

// Let's verify the PKCS7, and then examine the signing cert,
// and get the signing cert's public key.
let crypt = chilkat::Crypt2::new();

// Validate the signedData PKCS7, and replace the contents of bdPkcs7 with the extracted signed content.
if crypt.opaque_verify_bd(&bd_pkcs7).is_err() {
    println!("{}", crypt.last_error_text());
    return;
}

// The signed content is the DER of a certificate.
// In other words, bdPkcs7 now contains a certificate.
let cert = chilkat::Cert::new();
if cert.load_from_bd(&bd_pkcs7).is_err() {
    println!("{}", cert.last_error_text());
    return;
}

// Show some certificate information:
println!("Subject: {}", cert.subject_dn());
println!("Serial: {}", cert.serial_number());
println!("Issuer: {}", cert.issuer_dn());

// Let's get the cert's public key...
let pub_key = chilkat::PublicKey::new();
let _ = cert.get_public_key(&pub_key);

// OK, you now have the public key and can do whatever is needed..
println!("{}", pub_key.key_type());
println!("{}", pub_key.key_size());