Java
Java
Export Selected PFX Contents as PEM
See more PFX/P12 Examples
Demonstrates Pfx.ToPemEx, which exports selected PFX contents as PEM-formatted text with control over which parts are included and how private keys are encrypted.
Background. Private keys are written in PKCS #8 form. Supported key-encryption algorithms include
aes128, aes192, aes256, and 3des; leaving the algorithm empty produces unencrypted keys.Chilkat Java Downloads
import com.chilkatsoft.*;
public class ChilkatExample {
static {
try {
System.loadLibrary("chilkat");
} catch (UnsatisfiedLinkError e) {
System.err.println("Native code library failed to load.\n" + e);
System.exit(1);
}
}
public static void main(String argv[])
{
boolean success = false;
CkPfx pfx = new CkPfx();
// The file path is relative to the application's current working directory. An absolute path
// may also be used. Supply the path appropriate to your own environment.
// The PFX password should come from a secure source rather than being hard-coded.
String password = "myPfxPassword";
success = pfx.LoadPfxFile("qa_data/identity.pfx",password);
if (success == false) {
System.out.println(pfx.lastErrorText());
return;
}
// Export selected PFX contents as PEM-formatted text. The boolean arguments control what is
// included: extended attributes, and whether to omit private keys, certificates, or CA certificates.
boolean bExtendedAttrs = false;
boolean bNoKeys = false;
boolean bNoCerts = false;
boolean bNoCaCerts = false;
// Encrypt the exported private keys. Supported algorithms include aes128, aes192, aes256, and 3des;
// leave the algorithm empty for unencrypted keys. The key password should come from a secure source.
String keyPassword = "myKeyPassword";
String pem = pfx.toPemEx(bExtendedAttrs,bNoKeys,bNoCerts,bNoCaCerts,"aes256",keyPassword);
if (pfx.get_LastMethodSuccess() == false) {
System.out.println(pfx.lastErrorText());
return;
}
System.out.println(pem);
}
}