Sample code for 30+ languages & platforms
Lua Requires Chilkat v11.0.0+

Get Certificates from .p12 / .pfx

See more PFX/P12 Examples

A PKCS12 (.p12 / .pfx) is a container for holding a certificate, its private key, and the certs in the chain of authentication up to and possibly including the root CA cert. A .p12 is not required to contain certain things. It will contain whatever the creator of the .p12 decided to include. It's possible to contain just a private key, just a cert, many certs without private keys, or many certs with many private keys. Usually, a .p12 contains one certificate, its associated private key, and certificates in the chain of authentication.

Chilkat Lua Downloads

Lua

    -- In the following call to loadlib, change the path (./chilkat.dll) to the relative or absolute directory where the chilkat.dll, chilkat.so, or chilkat.dylib is located.
    chilkat = assert(package.loadlib("./chilkat.dll", "luaopen_chilkat"))()
    print(chilkat._VERSION)

    local success = false

    local pfx = chilkat.newPfx{}

    success = pfx:LoadPfxFile("qa_data/pfx/test.pfx","pfx_password")
    if success == false then
        print(pfx:LastErrorText())

    end

    --  Iterate over the certs contained in the PFX
    local cert = chilkat.newCert{}
    local numCerts = pfx:NumCerts()
    local i = 0
    while i < numCerts do

        pfx:CertAt(i,cert)

        print("--- ", i, " ---")
        print(cert:SubjectDN())
        --  Is this a root cert, or self-signed?
        print("Root: ", cert:IsRoot())
        print("Self-Signed: ", cert:SelfSigned())

        --  If this certificate is not the root (self-signed), then get the issuer.
        --  If the issuing certificate is contained in the PFX, then it will be found here..
        if cert:SelfSigned() ~= true then
            local issuer = cert:FindIssuer()
            if cert:LastMethodSuccess() == false then
                print("Issuer not found.")
            else
                print("Issuer: ", issuer:SubjectDN())

            end

        end

        i = i + 1
    end

    --  Usually, the user certificate is at index 0, its issuer is at index 1, etc. until we get to the root certificate.