Sample code for 30+ languages & platforms
Zig

openssl smime -encrypt -des3 -in <file> <pem file>

See more OpenSSL Examples

OpenSSL SMIME encrypt file using PEM containing a certificate.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // Load the cert from a PEM file.

    const pem = try chilkat.Pem.init();
    defer pem.deinit();
    // Our particular PEM was not encrypted, so we pass an empty password.
    // Also, a private key is not needed for encryption.  The PEM used to test this example
    // happens to have a private key, but it's not actually used.
    pem.loadPemFile("qa_data/openssl/rsaCertAndKey.pem", "") catch {
        std.debug.print("{s}\n", .{try pem.getLastErrorText(alloc)});
        return;
    };

    if (pem.getNumCerts() == 0) {
        std.debug.print("PEM does not contain any certificates.\n", .{});
        return;
    }

ERROR: Method not in the Zig package: Pem.GetCert
ERROR: Method not in the Zig package: Pem.GetCert
    const cert = pem.ERROR();
    if (!pem.getLastMethodSuccess()) {
        std.debug.print("{s}\n", .{try pem.getLastErrorText(alloc)});
        return;
    }

    // -------------------------------------------------------------------------------------
    // Duplicate this OpenSSL command:   openssl smime -encrypt -des3 -in <file> <pem file>
    // -------------------------------------------------------------------------------------
    const crypt = try chilkat.Crypt2.init();
    defer crypt.deinit();
    crypt.setEncryptCert(cert) catch {
        std.debug.print("{s}\n", .{try crypt.getLastErrorText(alloc)});

        return;
    };

    crypt.setCryptAlgorithm("PKI");
    crypt.setPkcs7CryptAlg("3des");
    crypt.setKeyLength(168);

    // Load the file to be encrypted.
    const bd = try chilkat.BinData.init();
    defer bd.deinit();
    bd.loadFile("qa_data/openssl/hello.txt") catch {
        std.debug.print("Failed to load the input file.\n", .{});
        return;
    };

    // Encrypt.
    crypt.encryptBd(bd) catch {
        std.debug.print("{s}\n", .{try crypt.getLastErrorText(alloc)});
        return;
    };

    // The openssl smime -encrypt command produces encrypte MIME such as this:

    // MIME-Version: 1.0
    // Content-Disposition: attachment; filename="smime.p7m"
    // Content-Type: application/x-pkcs7-mime; smime-type=enveloped-data; name="smime.p7m"
    // Content-Transfer-Encoding: base64
    //
    // MIICzwYJKoZIhvcNAQcDoIICwDCCArwCAQAxggF8MIIBeAIBADBgMEoxCzAJBgNVBAYTAlVTMRYw
    // FAYDVQQKEw1MZXQncyBFbmNyeXB0MSMwIQYDVQQDExpMZXQncyBFbmNyeXB0IEF1dGhvcml0eSBY
    // MwISA9Nqgb1dH/XTDNeKzN1nR85iMA0GCSqGSIb3DQEBAQUABIIBAIQqPexjxWovgxwKV/r3HL/U
    // EP9Yozvz5hBeX5VvRZjKSi4FRw5wapElPK+4FB82hiAR9Mi3c16PvPSVkJv3l78Mv5uaaOs/OmUz
    // mIHFB6Z+l2E52BDmUVWJZTQ09vdWy6+NIRlg2R9Z1NkmZ4BZCJk6mHB/Yx03IaOxK8LnwieDMthM
    // SvxbhJnIOISN7k7ofs+/0vTXUpdQ+tlmwyVySMGQ6VMk+z4sqZJ2stacqCPtt/aiSwJ9p0OKmihf
    // 3KDJceXJtavIQeA97yz1LqPvle35mmd5sBhV9qQYdTV/KJ+YM5uEZ9BHYbvMJbADFHwKzhcEY3qA
    // 7T9acmEsb7NycOIwggE1BgkqhkiG9w0BBwEwFAYIKoZIhvcNAwcECERX/ZoHweSkgIIBEMmCMx49
    // zjVAnGqRaBbvzQT1hg0uQSxIJjxMxC+HSuM+eY9oSOsbrw4uIijHKH9NdOpeDsdRzg2z5EBM7AlP
    // Ht9DyPW5C2deV6RPX4F8gyExz+JUXrd+3Yb3AKTdpDkTWDmNCeO0r/YSqp518+mfU5hG8e336u51
    // HAM44FeknA8oThWsD/wUB1e8vzsatK4UXW/KSu/166V7z+VT86kd+IHa7t60U9Yp0ZXgcM5Pb5Ni
    // 69Qc5MKPzom2801H5UR/WjCgsxOIjOj49sKisjRy79skrJzxY5ZG05T0dKn6KC3TjRpIEEeOyhCd
    // Nm2Y7dcW8GLMepdhWay5vePmQxmvmhbAtBprIem14NcrYeG6D5wP

    // We have the body in bd
    // Construct the header and base64 body...
    const sb_encrypted_mime = try chilkat.StringBuilder.init();
    defer sb_encrypted_mime.deinit();

    sb_encrypted_mime.appendLine("MIME-Version: 1.0", true) catch {};
    sb_encrypted_mime.appendLine("Content-Disposition: attachment; filename=\"smime.p7m\"", true) catch {};
    sb_encrypted_mime.appendLine("Content-Type: application/x-pkcs7-mime; smime-type=enveloped-data; name=\"smime.p7m\"", true) catch {};
    sb_encrypted_mime.appendLine("Content-Transfer-Encoding: base64", true) catch {};
    sb_encrypted_mime.appendLine("", true) catch {};
    sb_encrypted_mime.appendLine(try bd.getEncoded(alloc, "base64_mime"), true) catch {};

    // Show the result.
    std.debug.print("{s}\n", .{try sb_encrypted_mime.getAsString(alloc)});

    // or save to a file..
    try sb_encrypted_mime.writeFile("qa_output/encryptedMime.txt", "utf-8", false);
}