Tcl
Tcl
Encrypt File to PKCS7 .p7m
See more Encryption Examples
_LANGUAGE_ example to public-key encrypt a file creating a PKCS#7 .p7m file as output. Also demonstrates how to decrypt the .p7m to recover the original file.Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.
set crypt [new_CkCrypt2]
# Indicate the public-key encryption is to be used.
# Do this by setting the encryption algorithm equal
# to "PKI" (an acroynm for public-key infrastructure).
CkCrypt2_put_CryptAlgorithm $crypt "PKI"
# Indicate the inner symmetric encryption algorithm to be used.
# possible values are "aes", "des", "3des", and "rc2".
# For this example, we'll use 256-bit AES encryption.
CkCrypt2_put_Pkcs7CryptAlg $crypt "aes"
CkCrypt2_put_KeyLength $crypt 256
# To encrypt, only a certificate w/ public key is needed.
# (The certificate w/ private key is required for decryption.)
# The LoadFromFile method can load virtually any certificate format:
# 1. DER encoded binary X.509 (.CER)
# 2. Base-64 encoded X.509 (.CER)
# 3. Cryptographic Message Syntax Standard - PKCS #7 Certificates (.P7B)
# 4. PEM format
set encryptCert [new_CkCert]
set success [CkCert_LoadFromFile $encryptCert "/Users/chilkat/testData/cer/acme.cer"]
if {$success != 1} then {
puts [CkCert_lastErrorText $encryptCert]
delete_CkCrypt2 $crypt
delete_CkCert $encryptCert
exit
}
# Tell the crypt object to use the certificate for encrypting:
CkCrypt2_AddEncryptCert $crypt $encryptCert
# Encrypt a file, producing a .p7m as output.
# The input file is unchanged, the output .p7m contains the encrypted
# contents of the input file.
set inFile "/Users/chilkat/testData/pdf/sample.pdf"
set outFile "/Users/chilkat/testData/p7m/sample.pdf.p7m"
set success [CkCrypt2_CkEncryptFile $crypt $inFile $outFile]
if {$success != 1} then {
puts [CkCrypt2_lastErrorText $crypt]
delete_CkCrypt2 $crypt
delete_CkCert $encryptCert
exit
}
# For demonstration purposes, a different instance of the object will be used
# for decryption.
set decrypt [new_CkCrypt2]
# To decrypt, the certificate w/ private key is required. A PFX (also known
# as PKCS#12) is a common secure container for certs and private keys.
set pfxFilename "/Users/chilkat/testData/pfx/acme.pfx"
set pfxPassword "secret"
# Tell the component to look in the PFX file for certs and private keys.
set success [CkCrypt2_AddPfxSourceFile $decrypt $pfxFilename $pfxPassword]
if {$success != 1} then {
puts [CkCrypt2_lastErrorText $decrypt]
delete_CkCrypt2 $crypt
delete_CkCert $encryptCert
delete_CkCrypt2 $decrypt
exit
}
# Tell the decrypt object that PKI (public key encryption) is to be used
# for decryptiong.
CkCrypt2_put_CryptAlgorithm $decrypt "PKI"
# There is no need to set the Pkcs7Alg or KeyLength because this information
# is contained within the .p7m
# Decrypt the .p7m
set inFile "/Users/chilkat/testData/p7m/sample.pdf.p7m"
set outFile "/Users/chilkat/testData/pdf/recovered.pdf"
set success [CkCrypt2_CkDecryptFile $decrypt $inFile $outFile]
if {$success == 0} then {
puts [CkCrypt2_lastErrorText $decrypt]
delete_CkCrypt2 $crypt
delete_CkCert $encryptCert
delete_CkCrypt2 $decrypt
exit
}
puts "Success!"
delete_CkCrypt2 $crypt
delete_CkCert $encryptCert
delete_CkCrypt2 $decrypt