Sample code for 30+ languages & platforms
Delphi DLL

Export Selected PFX Contents as PEM

See more PFX/P12 Examples

Demonstrates Pfx.ToPemEx, which exports selected PFX contents as PEM-formatted text with control over which parts are included and how private keys are encrypted.

Background. Private keys are written in PKCS #8 form. Supported key-encryption algorithms include aes128, aes192, aes256, and 3des; leaving the algorithm empty produces unencrypted keys.

Chilkat Delphi DLL Downloads

Delphi DLL
var
success: Boolean;
pfx: HCkPfx;
password: PWideChar;
bExtendedAttrs: Boolean;
bNoKeys: Boolean;
bNoCerts: Boolean;
bNoCaCerts: Boolean;
keyPassword: PWideChar;
pem: PWideChar;

begin
success := False;

pfx := CkPfx_Create();

//  The file path is relative to the application's current working directory.  An absolute path
//  may also be used.  Supply the path appropriate to your own environment.
//  The PFX password should come from a secure source rather than being hard-coded.
password := 'myPfxPassword';
success := CkPfx_LoadPfxFile(pfx,'qa_data/identity.pfx',password);
if (success = False) then
  begin
    Memo1.Lines.Add(CkPfx__lastErrorText(pfx));
    Exit;
  end;

//  Export selected PFX contents as PEM-formatted text.  The boolean arguments control what is
//  included: extended attributes, and whether to omit private keys, certificates, or CA certificates.
bExtendedAttrs := False;
bNoKeys := False;
bNoCerts := False;
bNoCaCerts := False;

//  Encrypt the exported private keys.  Supported algorithms include aes128, aes192, aes256, and 3des;
//  leave the algorithm empty for unencrypted keys.  The key password should come from a secure source.
keyPassword := 'myKeyPassword';
pem := CkPfx__toPemEx(pfx,bExtendedAttrs,bNoKeys,bNoCerts,bNoCaCerts,'aes256',keyPassword);
if (CkPfx_getLastMethodSuccess(pfx) = False) then
  begin
    Memo1.Lines.Add(CkPfx__lastErrorText(pfx));
    Exit;
  end;
Memo1.Lines.Add(pem);

CkPfx_Dispose(pfx);