Sample code for 30+ languages & platforms
Xbase++ Requires Chilkat v11.0.0+

Create JWK Set Containing Certificates

See more Certificates Examples

Demonstrates how to create a JWK Set containing N certificates.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oCert1
LOCAL oCert2
LOCAL oCrypt
LOCAL oJson
LOCAL cHexThumbprint
LOCAL cBase64Thumbprint
LOCAL oPubKey
LOCAL oPubKeyJwk

nSuccess := 0

//  This example creates the following JWK Set from two certificates:

//  {
//    "keys": [
//      {
//        "kty": "RSA",
//        "use": "sig",
//        "kid": "BB8CeFVqyaGrGNuehJIiL4dfjzw",
//        "x5t": "BB8CeFVqyaGrGNuehJIiL4dfjzw",
//        "n": "nYf1jpn7cFdQ...9Iw",
//        "e": "AQAB",
//        "x5c": [
//          "MIIDBTCCAe2...Z+NTZo"
//        ]
//      },
//      {
//        "kty": "RSA",
//        "use": "sig",
//        "kid": "M6pX7RHoraLsprfJeRCjSxuURhc",
//        "x5t": "M6pX7RHoraLsprfJeRCjSxuURhc",
//        "n": "xHScZMPo8F...EO4QQ",
//        "e": "AQAB",
//        "x5c": [
//          "MIIC8TCCAdmgA...Vt5432GA=="
//        ]
//      }
//    ]
//  }

//  First get two certificates from files.
oCert1 := CreateObject("Chilkat.Cert")
nSuccess := oCert1:LoadFromFile("qa_data/certs/brasil_cert.pem")
IF (nSuccess == 0)
    ? oCert1:LastErrorText
    oCert1:destroy()
    RETURN
ENDIF

oCert2 := CreateObject("Chilkat.Cert")
nSuccess := oCert2:LoadFromFile("qa_data/certs/testCert.cer")
IF (nSuccess == 0)
    ? oCert2:LastErrorText
    oCert1:destroy()
    oCert2:destroy()
    RETURN
ENDIF

//  We'll need this crypt object re-encode the SHA1 thumbprint from hex to base64.
oCrypt := CreateObject("Chilkat.Crypt2")

oJson := CreateObject("Chilkat.JsonObject")

//  Let's begin with the 1st cert:
oJson:I := 0
oJson:UpdateString("keys[i].kty", "RSA")
oJson:UpdateString("keys[i].use", "sig")

cHexThumbprint := oCert1:Sha1Thumbprint
cBase64Thumbprint := oCrypt:ReEncode(cHexThumbprint, "hex", "base64")
oJson:UpdateString("keys[i].kid", cBase64Thumbprint)
oJson:UpdateString("keys[i].x5t", cBase64Thumbprint)

//  (We're assuming these are RSA certificates)
//  To get the modulus (n) and exponent (e), we need to get the cert's public key and then get its JWK.
oPubKey := CreateObject("Chilkat.PublicKey")
oCert1:GetPublicKey(oPubKey)

oPubKeyJwk := CreateObject("Chilkat.JsonObject")
oPubKeyJwk:Load(oPubKey:GetJwk())
oJson:UpdateString("keys[i].n", oPubKeyJwk:StringOf("n"))
oJson:UpdateString("keys[i].e", oPubKeyJwk:StringOf("e"))

//  Now add the entire X.509 certificate 
oJson:UpdateString("keys[i].x5c[0]", oCert1:GetEncoded())

//  Now do the same for cert2..
oJson:I := 1

oJson:UpdateString("keys[i].kty", "RSA")
oJson:UpdateString("keys[i].use", "sig")

cHexThumbprint := oCert2:Sha1Thumbprint
cBase64Thumbprint := oCrypt:ReEncode(cHexThumbprint, "hex", "base64")
oJson:UpdateString("keys[i].kid", cBase64Thumbprint)
oJson:UpdateString("keys[i].x5t", cBase64Thumbprint)
oCert2:GetPublicKey(oPubKey)

oPubKeyJwk:Load(oPubKey:GetJwk())
oJson:UpdateString("keys[i].n", oPubKeyJwk:StringOf("n"))
oJson:UpdateString("keys[i].e", oPubKeyJwk:StringOf("e"))

//  Now add the entire X.509 certificate 
oJson:UpdateString("keys[i].x5c[0]", oCert2:GetEncoded())

//  Emit the JSON..
oJson:EmitCompact := 0
? oJson:Emit()

oCert1:destroy()
oCert2:destroy()
oCrypt:destroy()
oJson:destroy()
oPubKey:destroy()
oPubKeyJwk:destroy()