Sample code for 30+ languages & platforms
Rust

Convert Let's Encrypt PEM Files to a PFX

See more PFX/P12 Examples

Demonstrates how to convert the .pem files provided by Let's Encrypt to a single PFX.

Chilkat Rust Downloads

Rust

// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

// Let's Encrypt provides four .pem files
// 1. fullchain.pem
// 2. privkey.pem
// 3. cert.pem
// 4. chain.pem

// The cert.pem and chain.pem are redundant. 
// The fullchain.pem is composed of the cert.pem and chain.pem.

// To convert the PEM's to a single .pfx, we don't need the redundant data.
// The privkey.pem and fullchain.pem provide the required data.
// We can ignore cert.pem and chain.pem (because those certs are already found in fullchain.pem).

// We need a single .pem file that contains both the private key, the cert,
// and the certs in the chain of authentication.
// Let's combine priveky.pem and fullchain.pem into a single .pem

let sb_pem = chilkat::StringBuilder::new();
if sb_pem.load_file("qa_data/pem/lets_encrypt/privkey.pem", "utf-8").is_err() {
    println!("Failed to load privkey.pem");
    return;
}

// To be safe, append a blank line..
let _ = sb_pem.append_line("", false);

let sb_full_chain_pem = chilkat::StringBuilder::new();
if sb_full_chain_pem.load_file("qa_data/pem/lets_encrypt/fullchain.pem", "utf-8").is_err() {
    println!("Failed to load fullchain.pem");
    return;
}

// Append the full cert chain PEM to the private key PEM.
let _ = sb_pem.append_sb(&sb_full_chain_pem);

// Load the combined PEM into a Chilkat PFX object.
let pfx = chilkat::Pfx::new();
if pfx.load_pem(&sb_pem.get_as_string().unwrap_or_default(), "no password required").is_err() {
    println!("{}", pfx.last_error_text());
    return;
}

// Write the PFX w/ a password.
let pfx_password = "secret".to_string();
if pfx.to_file(&pfx_password, "qa_output/sample.pfx").is_err() {
    println!("{}", pfx.last_error_text());
    return;
}

println!("Success!");