Sample code for 30+ languages & platforms
Lianja

Get Certificates from .p12 / .pfx

See more PFX/P12 Examples

A PKCS12 (.p12 / .pfx) is a container for holding a certificate, its private key, and the certs in the chain of authentication up to and possibly including the root CA cert. A .p12 is not required to contain certain things. It will contain whatever the creator of the .p12 decided to include. It's possible to contain just a private key, just a cert, many certs without private keys, or many certs with many private keys. Usually, a .p12 contains one certificate, its associated private key, and certificates in the chain of authentication.

Chilkat Lianja Downloads

Lianja
llSuccess = .F.

loPfx = createobject("CkPfx")

llSuccess = loPfx.LoadPfxFile("qa_data/pfx/test.pfx","pfx_password")
if (llSuccess = .F.) then
    ? loPfx.LastErrorText
    release loPfx
    return
endif

// Iterate over the certs contained in the PFX
loCert = createobject("CkCert")
lnNumCerts = loPfx.NumCerts
i = 0
do while i < lnNumCerts

    loPfx.CertAt(i,loCert)

    ? "--- " + str(i) + " ---"
    ? loCert.SubjectDN
    // Is this a root cert, or self-signed?
    ? "Root: " + str(loCert.IsRoot)
    ? "Self-Signed: " + str(loCert.SelfSigned)

    // If this certificate is not the root (self-signed), then get the issuer.
    // If the issuing certificate is contained in the PFX, then it will be found here..
    if (loCert.SelfSigned <> .T.) then
        loIssuer = loCert.FindIssuer()
        if (loCert.LastMethodSuccess = .F.) then
            ? "Issuer not found."
        else
            ? "Issuer: " + loIssuer.SubjectDN
            release loIssuer
        endif

    endif

    i = i + 1
enddo

// Usually, the user certificate is at index 0, its issuer is at index 1, etc. until we get to the root certificate.


release loPfx
release loCert