Sample code for 30+ languages & platforms
SQL Server

Set a PFX Safe-Bag Attribute

See more PFX/P12 Examples

Demonstrates Pfx.SetSafeBagAttr, which sets a safe-bag attribute on a private key or certificate inside the PFX.

The file path is relative to the application's current working directory. An absolute path may also be used. Supply the path appropriate to your own environment.

Background. A safe-bag attribute is metadata attached to an item inside a PKCS#12/PFX container; it does not change the certificate or private-key material. Recognized attributes include friendlyName, keyContainerName, keyName, and localKeyId. The encoding argument names the value's binary representation for binary attributes and is ignored for text-valued attributes such as friendlyName.

Chilkat SQL Server Downloads

SQL Server
-- Important: See this note about string length limitations for strings returned by sp_OAMethod calls.
--
CREATE PROCEDURE ChilkatSample
AS
BEGIN
    DECLARE @hr int
    DECLARE @sTmp0 nvarchar(4000)
    DECLARE @success int
    SELECT @success = 0

    DECLARE @pfx int
    EXEC @hr = sp_OACreate 'Chilkat.Pfx', @pfx OUT
    IF @hr <> 0
    BEGIN
        PRINT 'Failed to create ActiveX component'
        RETURN
    END

    --  The file path is relative to the application's current working directory.  An absolute path
    --  may also be used.  Supply the path appropriate to your own environment.
    --  The PFX password should come from a secure source rather than being hard-coded.
    DECLARE @password nvarchar(4000)
    SELECT @password = 'myPfxPassword'
    EXEC sp_OAMethod @pfx, 'LoadPfxFile', @success OUT, 'qa_data/identity.pfx', @password
    IF @success = 0
      BEGIN
        EXEC sp_OAGetProperty @pfx, 'LastErrorText', @sTmp0 OUT
        PRINT @sTmp0
        EXEC @hr = sp_OADestroy @pfx
        RETURN
      END

    --  Set a safe-bag attribute on an item inside the PFX.  Safe-bag attributes are metadata attached to
    --  an item in the container; they do not change the certificate or key material itself.  The 1st
    --  argument is 1 for a private key or 0 for a certificate, and the 2nd is the zero-based
    --  index within that collection.
    DECLARE @bForPrivateKey int
    SELECT @bForPrivateKey = 1

    --  friendlyName is a text-valued attribute, so the encoding argument is ignored (pass an empty
    --  string).  For binary attributes such as localKeyId, the encoding names the value's representation.
    EXEC sp_OAMethod @pfx, 'SetSafeBagAttr', @success OUT, @bForPrivateKey, 0, 'friendlyName', 'My Identity', ''
    IF @success = 0
      BEGIN
        EXEC sp_OAGetProperty @pfx, 'LastErrorText', @sTmp0 OUT
        PRINT @sTmp0
        EXEC @hr = sp_OADestroy @pfx
        RETURN
      END

    PRINT 'Safe-bag attribute set.'

    EXEC @hr = sp_OADestroy @pfx


END
GO