Sample code for 30+ languages & platforms
Rust Requires Chilkat v11.0.0+

Get Certificates from .p12 / .pfx

See more PFX/P12 Examples

A PKCS12 (.p12 / .pfx) is a container for holding a certificate, its private key, and the certs in the chain of authentication up to and possibly including the root CA cert. A .p12 is not required to contain certain things. It will contain whatever the creator of the .p12 decided to include. It's possible to contain just a private key, just a cert, many certs without private keys, or many certs with many private keys. Usually, a .p12 contains one certificate, its associated private key, and certificates in the chain of authentication.

Chilkat Rust Downloads

Rust

let pfx = chilkat::Pfx::new();

if pfx.load_pfx_file("qa_data/pfx/test.pfx", "pfx_password").is_err() {
    println!("{}", pfx.last_error_text());
    return;
}

// Iterate over the certs contained in the PFX
let cert = chilkat::Cert::new();
let num_certs = pfx.num_certs();
let mut i = 0;
while i < num_certs {

    let _ = pfx.cert_at(i, &cert);

    println!("--- {} ---", i);
    println!("{}", cert.subject_dn());
    // Is this a root cert, or self-signed?
    println!("Root: {}", cert.is_root());
    println!("Self-Signed: {}", cert.self_signed());

    // If this certificate is not the root (self-signed), then get the issuer.
    // If the issuing certificate is contained in the PFX, then it will be found here..
    if !cert.self_signed() {
        let issuer = cert.find_issuer().unwrap();
        if !cert.last_method_success() {
            println!("Issuer not found.");
        } else {
            println!("Issuer: {}", issuer.subject_dn());

        }

    }

    i = i + 1;
}

// Usually, the user certificate is at index 0, its issuer is at index 1, etc. until we get to the root certificate.