Chilkat HOME Android™ AutoIt C C# C++ Chilkat2-Python CkPython Classic ASP DataFlex Delphi DLL Go Java Node.js Objective-C PHP Extension Perl PowerBuilder PowerShell PureBasic Ruby SQL Server Swift Tcl Unicode C Unicode C++ VB.NET VBScript Visual Basic 6.0 Visual FoxPro Xojo Plugin
(Swift) Create JWK Set Containing CertificatesDemonstrates how to create a JWK Set containing N certificates.
func chilkatTest() { // This example creates the following JWK Set from two certificates: // { // "keys": [ // { // "kty": "RSA", // "use": "sig", // "kid": "BB8CeFVqyaGrGNuehJIiL4dfjzw", // "x5t": "BB8CeFVqyaGrGNuehJIiL4dfjzw", // "n": "nYf1jpn7cFdQ...9Iw", // "e": "AQAB", // "x5c": [ // "MIIDBTCCAe2...Z+NTZo" // ] // }, // { // "kty": "RSA", // "use": "sig", // "kid": "M6pX7RHoraLsprfJeRCjSxuURhc", // "x5t": "M6pX7RHoraLsprfJeRCjSxuURhc", // "n": "xHScZMPo8F...EO4QQ", // "e": "AQAB", // "x5c": [ // "MIIC8TCCAdmgA...Vt5432GA==" // ] // } // ] // } // First get two certificates from files. let cert1 = CkoCert()! var success: Bool = cert1.load(fromFile: "qa_data/certs/brasil_cert.pem") if success != true { print("\(cert1.lastErrorText!)") return } let cert2 = CkoCert()! success = cert2.load(fromFile: "qa_data/certs/testCert.cer") if success != true { print("\(cert2.lastErrorText!)") return } // We'll need this crypt object re-encode the SHA1 thumbprint from hex to base64. let crypt = CkoCrypt2()! let json = CkoJsonObject()! // Let's begin with the 1st cert: json.i = 0 json.update("keys[i].kty", value: "RSA") json.update("keys[i].use", value: "sig") var hexThumbprint: String? = cert1.sha1Thumbprint var base64Thumbprint: String? = crypt.reEncode(hexThumbprint, fromEncoding: "hex", toEncoding: "base64") json.update("keys[i].kid", value: base64Thumbprint) json.update("keys[i].x5t", value: base64Thumbprint) // (We're assuming these are RSA certificates) // To get the modulus (n) and exponent (e), we need to get the cert's public key and then get its JWK. var pubKey: CkoPublicKey? = cert1.exportPublicKey() let pubKeyJwk = CkoJsonObject()! pubKeyJwk.load(pubKey!.getJwk()) pubKey = nil json.update("keys[i].n", value: pubKeyJwk.string(of: "n")) json.update("keys[i].e", value: pubKeyJwk.string(of: "e")) // Now add the entire X.509 certificate json.update("keys[i].x5c[0]", value: cert1.getEncoded()) // Now do the same for cert2.. json.i = 1 json.update("keys[i].kty", value: "RSA") json.update("keys[i].use", value: "sig") hexThumbprint = cert2.sha1Thumbprint base64Thumbprint = crypt.reEncode(hexThumbprint, fromEncoding: "hex", toEncoding: "base64") json.update("keys[i].kid", value: base64Thumbprint) json.update("keys[i].x5t", value: base64Thumbprint) pubKey = cert2.exportPublicKey() pubKeyJwk.load(pubKey!.getJwk()) pubKey = nil json.update("keys[i].n", value: pubKeyJwk.string(of: "n")) json.update("keys[i].e", value: pubKeyJwk.string(of: "e")) // Now add the entire X.509 certificate json.update("keys[i].x5c[0]", value: cert2.getEncoded()) // Emit the JSON.. json.emitCompact = false print("\(json.emit()!)") } |
© 2000-2025 Chilkat Software, Inc. All Rights Reserved.