PowerShell
PowerShell
Export a Private Key as DER into a BinData
See more Private Key Examples
Demonstrates the Chilkat PrivateKey.GetPkcsBd method, which exports the key as DER into a BinData. The first argument selects PKCS #1 (true) versus PKCS #8 (false), the second is the password (empty for unencrypted), and the third is the BinData that receives the bytes.
Note: The file paths are relative to the application's current working directory. Absolute paths may also be used. Supply the paths appropriate to your own environment.
Background: This is the in-memory binary export — the raw DER bytes land in a
BinData ready to hash, encrypt, or hand to another API without a temporary file. One method covers several cases: the boolean picks the traditional (PKCS #1) versus modern (PKCS #8) structure, and a nonempty password produces an encrypted PKCS #8 export (with the cipher from Pkcs8EncryptAlg). Source any password securely.Chilkat PowerShell Downloads
Add-Type -Path "C:\chilkat\ChilkatDotNet47-x64\ChilkatDotNet47.dll"
$success = $false
# Load a private key to export.
$privKey = New-Object Chilkat.PrivateKey
$success = $privKey.LoadPemFile("qa_data/private.pem")
if ($success -eq $false) {
$($privKey.LastErrorText)
exit
}
# The key password is not hard-coded in a real application; obtain it from an interactive
# prompt, environment variable, or a secrets vault.
$password = "myKeyPassword"
# Export the key as DER into a BinData. The 1st argument selects PKCS #1 ($true) versus PKCS #8
# ($false); the 2nd is the password (empty string for an unencrypted export); the 3rd is the
# BinData that receives the DER bytes.
$usePkcs1 = $false
$bd = New-Object Chilkat.BinData
$success = $privKey.GetPkcsBd($usePkcs1,$password,$bd)
if ($success -eq $false) {
$($privKey.LastErrorText)
exit
}
$("Exported " + $bd.NumBytes + " DER bytes.")