Sample code for 30+ languages & platforms
Tcl

Enumerate Certificates in a PFX

See more PFX/P12 Examples

Demonstrates Pfx.CertAt, which copies the certificate at a zero-based index into a Cert object. The example enumerates all certificates in the PFX.

The file path is relative to the application's current working directory. An absolute path may also be used. Supply the path appropriate to your own environment.

Background. Valid indexes are less than NumCerts. Each retrieved certificate is an independent copy that can be inspected or used separately.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

set pfx [new_CkPfx]

#  The file path is relative to the application's current working directory.  An absolute path
#  may also be used.  Supply the path appropriate to your own environment.
#  The PFX password should come from a secure source rather than being hard-coded.
set password "myPfxPassword"
set success [CkPfx_LoadPfxFile $pfx "qa_data/identity.pfx" $password]
if {$success == 0} then {
    puts [CkPfx_lastErrorText $pfx]
    delete_CkPfx $pfx
    exit
}

#  Enumerate the certificates in the PFX by zero-based index.  Valid indexes are less than NumCerts.
#  The certificate at index 0 is typically the certificate that has a private key, and the remaining
#  certificates are the others in its certificate chain.
set numCerts [CkPfx_get_NumCerts $pfx]
set cert [new_CkCert]

for {set i 0} {$i <= [expr $numCerts - 1]} {incr i} {
    set success [CkPfx_CertAt $pfx $i $cert]
    if {$success == 0} then {
        puts [CkPfx_lastErrorText $pfx]
        delete_CkPfx $pfx
        delete_CkCert $cert
        exit
    }

    puts "Certificate $i: [CkCert_subjectCN $cert]"
}

delete_CkPfx $pfx
delete_CkCert $cert