Sample code for 30+ languages & platforms
Pascal (Lazarus/Delphi)

Export Selected PFX Contents as PEM

See more PFX/P12 Examples

Demonstrates Pfx.ToPemEx, which exports selected PFX contents as PEM-formatted text with control over which parts are included and how private keys are encrypted.

Background. Private keys are written in PKCS #8 form. Supported key-encryption algorithms include aes128, aes192, aes256, and 3des; leaving the algorithm empty produces unencrypted keys.

Chilkat Pascal (Lazarus/Delphi) Downloads

Pascal (Lazarus/Delphi)
program ChilkatDemo;

// Demonstrates using the Chilkat Pascal wrapper via the C bridge DLL.
// Builds as a console application under Lazarus (FPC) or Delphi.

{$IFDEF FPC}
  {$MODE DELPHI}
{$ENDIF}
{$APPTYPE CONSOLE}

uses
  {$IFDEF UNIX}
  cthreads,
  {$ENDIF}
  SysUtils,
  CkDllLoader,
  Chilkat.Pfx;

// ---------------------------------------------------------------------------

procedure RunDemo;
var
  success: Boolean;
  pfx: TPfx;
  password: string;
  bExtendedAttrs: Boolean;
  bNoKeys: Boolean;
  bNoCerts: Boolean;
  bNoCaCerts: Boolean;
  keyPassword: string;
  pem: string;

begin
  success := False;

  pfx := TPfx.Create;

  //  The file path is relative to the application's current working directory.  An absolute path
  //  may also be used.  Supply the path appropriate to your own environment.
  //  The PFX password should come from a secure source rather than being hard-coded.
  password := 'myPfxPassword';
  success := pfx.LoadPfxFile('qa_data/identity.pfx',password);
  if (success = False) then
    begin
      WriteLn(pfx.LastErrorText);
      Exit;
    end;

  //  Export selected PFX contents as PEM-formatted text.  The boolean arguments control what is
  //  included: extended attributes, and whether to omit private keys, certificates, or CA certificates.
  bExtendedAttrs := False;
  bNoKeys := False;
  bNoCerts := False;
  bNoCaCerts := False;

  //  Encrypt the exported private keys.  Supported algorithms include aes128, aes192, aes256, and 3des;
  //  leave the algorithm empty for unencrypted keys.  The key password should come from a secure source.
  keyPassword := 'myKeyPassword';
  pem := pfx.ToPemEx(bExtendedAttrs,bNoKeys,bNoCerts,bNoCaCerts,'aes256',keyPassword);
  if (pfx.LastMethodSuccess = False) then
    begin
      WriteLn(pfx.LastErrorText);
      Exit;
    end;
  WriteLn(pem);


  pfx.Free;

end;

// ---------------------------------------------------------------------------

begin

  try
    RunDemo;
  except
    on E: Exception do
      WriteLn('Unhandled exception: ', E.ClassName, ': ', E.Message);
  end;

  WriteLn;
  {$IFDEF MSWINDOWS}
  WriteLn('Press Enter to exit...');
  ReadLn;
  {$ENDIF}
end.