Sample code for 30+ languages & platforms
Tcl Requires Chilkat v11.0.0+

Encrypt with Chilkat, Decrypt with OpenSSL

See more OpenSSL Examples

Demonstrates how to RSA encrypt a string using Chilkat, and then shows the corresponding OpenSSL command to RSA decrypt. The OpenSSL command to decrypt is as follows:
openssl rsautl -decrypt -inkey VP_Private.pem -in rsa_encrypted.bin -out original.txt

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

#  This example requires the Chilkat API to have been previously unlocked.
#  See Global Unlock Sample for sample code.

set rsa [new_CkRsa]

#  Note: RSA encryption uses the public key.  
#  RSA decryption uses the private key.
#  The reason is that the public key can be freely provided to anybody.  This allows anybody
#  to send an encrypted message to the private key owner, and only the private key owner 
#  can decrypt.
set key [new_CkPublicKey]

#  Load an RSA public key from a PEM file:
set success [CkPublicKey_LoadFromFile $key "qa_data/pem/VP_Public.pem"]
if {$success == 0} then {
    puts [CkPublicKey_lastErrorText $key]
    delete_CkRsa $rsa
    delete_CkPublicKey $key
    exit
}

#  Load the public key into the RSA object.
set success [CkRsa_UsePublicKey $rsa $key]
if {$success == 0} then {
    puts [CkRsa_lastErrorText $rsa]
    delete_CkRsa $rsa
    delete_CkPublicKey $key
    exit
}

set strToEncrypt "00000000;XYZ2-3BHQ-ABCD-MMVV;6MY1-GHJK-9LRR;0"

#  The LittleEndian property is 0 by default, but it is set here
#  anyway to show that LittleEndian byte ordering is required for OpenSSL compatibility.
CkRsa_put_LittleEndian $rsa 0

set usePrivateKey 0
set encryptedBytes [new_CkByteData]

set success [CkRsa_EncryptString $rsa $strToEncrypt $usePrivateKey $encryptedBytes]
if {[CkRsa_get_LastMethodSuccess $rsa] == 0} then {
    puts [CkRsa_lastErrorText $rsa]
    delete_CkRsa $rsa
    delete_CkPublicKey $key
    delete_CkByteData $encryptedBytes
    exit
}

#  The OpenSSL command to decrypt would be this:
#  openssl rsautl -decrypt -inkey VP_Private.pem -in rsa_encrypted.bin -out original.txt

set fac [new_CkFileAccess]

set success [CkFileAccess_WriteEntireFile $fac "qa_output/rsa_encrypted.bin" $encryptedBytes]
if {$success == 0} then {
    puts [CkFileAccess_lastErrorText $fac]
    delete_CkRsa $rsa
    delete_CkPublicKey $key
    delete_CkByteData $encryptedBytes
    delete_CkFileAccess $fac
    exit
}

puts "RSA Encryption Succeeded."

delete_CkRsa $rsa
delete_CkPublicKey $key
delete_CkByteData $encryptedBytes
delete_CkFileAccess $fac