Tcl
Tcl
openssl smime -encrypt -des3 -in <file> <pem file>
See more OpenSSL Examples
OpenSSL SMIME encrypt file using PEM containing a certificate.Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.
# Load the cert from a PEM file.
set pem [new_CkPem]
# Our particular PEM was not encrypted, so we pass an empty password.
# Also, a private key is not needed for encryption. The PEM used to test this example
# happens to have a private key, but it's not actually used.
set success [CkPem_LoadPemFile $pem "qa_data/openssl/rsaCertAndKey.pem" ""]
if {$success == 0} then {
puts [CkPem_lastErrorText $pem]
delete_CkPem $pem
exit
}
if {[CkPem_get_NumCerts $pem] == 0} then {
puts "PEM does not contain any certificates."
delete_CkPem $pem
exit
}
# cert is a CkCert
set cert [CkPem_GetCert $pem 0]
if {[CkPem_get_LastMethodSuccess $pem] == 0} then {
puts [CkPem_lastErrorText $pem]
delete_CkPem $pem
exit
}
# -------------------------------------------------------------------------------------
# Duplicate this OpenSSL command: openssl smime -encrypt -des3 -in <file> <pem file>
# -------------------------------------------------------------------------------------
set crypt [new_CkCrypt2]
set success [CkCrypt2_SetEncryptCert $crypt $cert]
if {$success == 0} then {
puts [CkCrypt2_lastErrorText $crypt]
delete_CkCert $cert
delete_CkPem $pem
delete_CkCrypt2 $crypt
exit
}
delete_CkCert $cert
CkCrypt2_put_CryptAlgorithm $crypt "PKI"
CkCrypt2_put_Pkcs7CryptAlg $crypt "3des"
CkCrypt2_put_KeyLength $crypt 168
# Load the file to be encrypted.
set bd [new_CkBinData]
set success [CkBinData_LoadFile $bd "qa_data/openssl/hello.txt"]
if {$success == 0} then {
puts "Failed to load the input file."
delete_CkPem $pem
delete_CkCrypt2 $crypt
delete_CkBinData $bd
exit
}
# Encrypt.
set success [CkCrypt2_EncryptBd $crypt $bd]
if {$success == 0} then {
puts [CkCrypt2_lastErrorText $crypt]
delete_CkPem $pem
delete_CkCrypt2 $crypt
delete_CkBinData $bd
exit
}
# The openssl smime -encrypt command produces encrypte MIME such as this:
# MIME-Version: 1.0
# Content-Disposition: attachment; filename="smime.p7m"
# Content-Type: application/x-pkcs7-mime; smime-type=enveloped-data; name="smime.p7m"
# Content-Transfer-Encoding: base64
#
# MIICzwYJKoZIhvcNAQcDoIICwDCCArwCAQAxggF8MIIBeAIBADBgMEoxCzAJBgNVBAYTAlVTMRYw
# FAYDVQQKEw1MZXQncyBFbmNyeXB0MSMwIQYDVQQDExpMZXQncyBFbmNyeXB0IEF1dGhvcml0eSBY
# MwISA9Nqgb1dH/XTDNeKzN1nR85iMA0GCSqGSIb3DQEBAQUABIIBAIQqPexjxWovgxwKV/r3HL/U
# EP9Yozvz5hBeX5VvRZjKSi4FRw5wapElPK+4FB82hiAR9Mi3c16PvPSVkJv3l78Mv5uaaOs/OmUz
# mIHFB6Z+l2E52BDmUVWJZTQ09vdWy6+NIRlg2R9Z1NkmZ4BZCJk6mHB/Yx03IaOxK8LnwieDMthM
# SvxbhJnIOISN7k7ofs+/0vTXUpdQ+tlmwyVySMGQ6VMk+z4sqZJ2stacqCPtt/aiSwJ9p0OKmihf
# 3KDJceXJtavIQeA97yz1LqPvle35mmd5sBhV9qQYdTV/KJ+YM5uEZ9BHYbvMJbADFHwKzhcEY3qA
# 7T9acmEsb7NycOIwggE1BgkqhkiG9w0BBwEwFAYIKoZIhvcNAwcECERX/ZoHweSkgIIBEMmCMx49
# zjVAnGqRaBbvzQT1hg0uQSxIJjxMxC+HSuM+eY9oSOsbrw4uIijHKH9NdOpeDsdRzg2z5EBM7AlP
# Ht9DyPW5C2deV6RPX4F8gyExz+JUXrd+3Yb3AKTdpDkTWDmNCeO0r/YSqp518+mfU5hG8e336u51
# HAM44FeknA8oThWsD/wUB1e8vzsatK4UXW/KSu/166V7z+VT86kd+IHa7t60U9Yp0ZXgcM5Pb5Ni
# 69Qc5MKPzom2801H5UR/WjCgsxOIjOj49sKisjRy79skrJzxY5ZG05T0dKn6KC3TjRpIEEeOyhCd
# Nm2Y7dcW8GLMepdhWay5vePmQxmvmhbAtBprIem14NcrYeG6D5wP
# We have the body in bd
# Construct the header and base64 body...
set sbEncryptedMime [new_CkStringBuilder]
CkStringBuilder_AppendLine $sbEncryptedMime "MIME-Version: 1.0" 1
CkStringBuilder_AppendLine $sbEncryptedMime "Content-Disposition: attachment; filename=\"smime.p7m\"" 1
CkStringBuilder_AppendLine $sbEncryptedMime "Content-Type: application/x-pkcs7-mime; smime-type=enveloped-data; name=\"smime.p7m\"" 1
CkStringBuilder_AppendLine $sbEncryptedMime "Content-Transfer-Encoding: base64" 1
CkStringBuilder_AppendLine $sbEncryptedMime "" 1
CkStringBuilder_AppendLine $sbEncryptedMime [CkBinData_getEncoded $bd "base64_mime"] 1
# Show the result.
puts [CkStringBuilder_getAsString $sbEncryptedMime]
# or save to a file..
set success [CkStringBuilder_WriteFile $sbEncryptedMime "qa_output/encryptedMime.txt" "utf-8" 0]
delete_CkPem $pem
delete_CkCrypt2 $crypt
delete_CkBinData $bd
delete_CkStringBuilder $sbEncryptedMime