Pascal (Lazarus/Delphi)
Pascal (Lazarus/Delphi)
Save a Private Key as an Encrypted PKCS #8 DER File
See more Private Key Examples
Demonstrates the Chilkat PrivateKey.SavePkcs8EncryptedFile method, which saves the key as password-protected PKCS #8 DER. The first argument is the password and the second is the destination path. The cipher is selected by Pkcs8EncryptAlg.
Note: The file paths are relative to the application's current working directory. Absolute paths may also be used. Supply the paths appropriate to your own environment.
Background: This is the recommended way to persist a key to disk: the binary
.der is encrypted under a passphrase, so a stolen file is useless without it. Reach for it whenever a key is stored or shipped. Choose the encryption cipher with Pkcs8EncryptAlg and source the password securely.Chilkat Pascal (Lazarus/Delphi) Downloads
program ChilkatDemo;
// Demonstrates using the Chilkat Pascal wrapper via the C bridge DLL.
// Builds as a console application under Lazarus (FPC) or Delphi.
{$IFDEF FPC}
{$MODE DELPHI}
{$ENDIF}
{$APPTYPE CONSOLE}
uses
{$IFDEF UNIX}
cthreads,
{$ENDIF}
SysUtils,
CkDllLoader,
Chilkat.PrivateKey;
// ---------------------------------------------------------------------------
procedure RunDemo;
var
success: Boolean;
privKey: TPrivateKey;
password: string;
begin
success := False;
// Load a private key to export.
privKey := TPrivateKey.Create;
success := privKey.LoadPemFile('qa_data/private.pem');
if (success = False) then
begin
WriteLn(privKey.LastErrorText);
Exit;
end;
// The key password is not hard-coded in a real application; obtain it from an interactive
// prompt, environment variable, or a secrets vault.
password := 'myKeyPassword';
// Save as password-protected PKCS #8 DER. The 1st argument is the password and the 2nd is the
// destination path. The cipher is selected by the Pkcs8EncryptAlg property.
success := privKey.SavePkcs8EncryptedFile(password,'qa_output/private_pkcs8_enc.der');
if (success = False) then
begin
WriteLn(privKey.LastErrorText);
Exit;
end;
WriteLn('Saved (encrypted).');
privKey.Free;
end;
// ---------------------------------------------------------------------------
begin
try
RunDemo;
except
on E: Exception do
WriteLn('Unhandled exception: ', E.ClassName, ': ', E.Message);
end;
WriteLn;
{$IFDEF MSWINDOWS}
WriteLn('Press Enter to exit...');
ReadLn;
{$ENDIF}
end.