Sample code for 30+ languages & platforms
Objective-C

Export Selected PFX Contents as PEM

See more PFX/P12 Examples

Demonstrates Pfx.ToPemEx, which exports selected PFX contents as PEM-formatted text with control over which parts are included and how private keys are encrypted.

Background. Private keys are written in PKCS #8 form. Supported key-encryption algorithms include aes128, aes192, aes256, and 3des; leaving the algorithm empty produces unencrypted keys.

Chilkat Objective-C Downloads

Objective-C
#import <CkoPfx.h>
#import <NSString.h>

BOOL success = NO;

CkoPfx *pfx = [[CkoPfx alloc] init];

//  The file path is relative to the application's current working directory.  An absolute path
//  may also be used.  Supply the path appropriate to your own environment.
//  The PFX password should come from a secure source rather than being hard-coded.
NSString *password = @"myPfxPassword";
success = [pfx LoadPfxFile: @"qa_data/identity.pfx" password: password];
if (success == NO) {
    NSLog(@"%@",pfx.LastErrorText);
    return;
}

//  Export selected PFX contents as PEM-formatted text.  The boolean arguments control what is
//  included: extended attributes, and whether to omit private keys, certificates, or CA certificates.
BOOL bExtendedAttrs = NO;
BOOL bNoKeys = NO;
BOOL bNoCerts = NO;
BOOL bNoCaCerts = NO;

//  Encrypt the exported private keys.  Supported algorithms include aes128, aes192, aes256, and 3des;
//  leave the algorithm empty for unencrypted keys.  The key password should come from a secure source.
NSString *keyPassword = @"myKeyPassword";
NSString *pem = [pfx ToPemEx: bExtendedAttrs noKeys: bNoKeys noCerts: bNoCerts noCaCerts: bNoCaCerts encryptAlg: @"aes256" password: keyPassword];
if (pfx.LastMethodSuccess == NO) {
    NSLog(@"%@",pfx.LastErrorText);
    return;
}

NSLog(@"%@",pem);