Sample code for 30+ languages & platforms
DataFlex

Set a PFX Safe-Bag Attribute

See more PFX/P12 Examples

Demonstrates Pfx.SetSafeBagAttr, which sets a safe-bag attribute on a private key or certificate inside the PFX.

The file path is relative to the application's current working directory. An absolute path may also be used. Supply the path appropriate to your own environment.

Background. A safe-bag attribute is metadata attached to an item inside a PKCS#12/PFX container; it does not change the certificate or private-key material. Recognized attributes include friendlyName, keyContainerName, keyName, and localKeyId. The encoding argument names the value's binary representation for binary attributes and is ignored for text-valued attributes such as friendlyName.

Chilkat DataFlex Downloads

DataFlex
Use ChilkatAx-win32.pkg

Procedure Test
    Boolean iSuccess
    Handle hoPfx
    String sPassword
    Boolean iBForPrivateKey
    String sTemp1

    Move False To iSuccess

    Get Create (RefClass(cComChilkatPfx)) To hoPfx
    If (Not(IsComObjectCreated(hoPfx))) Begin
        Send CreateComObject of hoPfx
    End

    //  The file path is relative to the application's current working directory.  An absolute path
    //  may also be used.  Supply the path appropriate to your own environment.
    //  The PFX password should come from a secure source rather than being hard-coded.
    Move "myPfxPassword" To sPassword
    Get ComLoadPfxFile Of hoPfx "qa_data/identity.pfx" sPassword To iSuccess
    If (iSuccess = False) Begin
        Get ComLastErrorText Of hoPfx To sTemp1
        Showln sTemp1
        Procedure_Return
    End

    //  Set a safe-bag attribute on an item inside the PFX.  Safe-bag attributes are metadata attached to
    //  an item in the container; they do not change the certificate or key material itself.  The 1st
    //  argument is True for a private key or False for a certificate, and the 2nd is the zero-based
    //  index within that collection.
    Move True To iBForPrivateKey

    //  friendlyName is a text-valued attribute, so the encoding argument is ignored (pass an empty
    //  string).  For binary attributes such as localKeyId, the encoding names the value's representation.
    Get ComSetSafeBagAttr Of hoPfx iBForPrivateKey 0 "friendlyName" "My Identity" "" To iSuccess
    If (iSuccess = False) Begin
        Get ComLastErrorText Of hoPfx To sTemp1
        Showln sTemp1
        Procedure_Return
    End

    Showln "Safe-bag attribute set."


End_Procedure