Sample code for 30+ languages & platforms
C

Convert a PFX to a Java KeyStore

See more PFX/P12 Examples

Demonstrates Pfx.ToJksObj, which populates a JavaKeyStore with a JKS representation of the PFX, then writes it to a file.

The file path is relative to the application's current working directory. An absolute path may also be used. Supply the path appropriate to your own environment.

Background. One private-key entry is created for each private key, with certificate chains built from the PFX certificates. The password protects the generated Java KeyStore.

Chilkat C Downloads

C
#include <C_CkPfx.h>
#include <C_CkJavaKeyStore.h>

void ChilkatSample(void)
    {
    BOOL success;
    HCkPfx pfx;
    const char *password;
    const char *jksPassword;
    HCkJavaKeyStore jks;

    success = FALSE;

    pfx = CkPfx_Create();

    //  The file path is relative to the application's current working directory.  An absolute path
    //  may also be used.  Supply the path appropriate to your own environment.
    //  The PFX password should come from a secure source rather than being hard-coded.
    password = "myPfxPassword";
    success = CkPfx_LoadPfxFile(pfx,"qa_data/identity.pfx",password);
    if (success == FALSE) {
        printf("%s\n",CkPfx_lastErrorText(pfx));
        CkPfx_Dispose(pfx);
        return;
    }

    //  Populate a Java KeyStore (JKS) representation of this PFX.  One private-key entry is created for
    //  each private key, and the PFX certificates are used to build the certificate chains.  The 1st
    //  argument is the alias for the first private-key entry, and the 2nd protects the generated JKS.
    //  The JKS password should come from a secure source rather than being hard-coded.
    jksPassword = "myJksPassword";
    jks = CkJavaKeyStore_Create();
    success = CkPfx_ToJksObj(pfx,"myalias",jksPassword,jks);
    if (success == FALSE) {
        printf("%s\n",CkPfx_lastErrorText(pfx));
        CkPfx_Dispose(pfx);
        CkJavaKeyStore_Dispose(jks);
        return;
    }

    //  The Java KeyStore object can then be written to a .jks file.
    success = CkJavaKeyStore_ToFile(jks,jksPassword,"qa_output/identity.jks");
    if (success == FALSE) {
        printf("%s\n",CkJavaKeyStore_lastErrorText(jks));
        CkPfx_Dispose(pfx);
        CkJavaKeyStore_Dispose(jks);
        return;
    }

    printf("Wrote a Java KeyStore with %d private key(s).\n",CkJavaKeyStore_getNumPrivateKeys(jks));


    CkPfx_Dispose(pfx);
    CkJavaKeyStore_Dispose(jks);

    }