Sample code for 30+ languages & platforms
Tcl

Set a PFX Safe-Bag Attribute

See more PFX/P12 Examples

Demonstrates Pfx.SetSafeBagAttr, which sets a safe-bag attribute on a private key or certificate inside the PFX.

The file path is relative to the application's current working directory. An absolute path may also be used. Supply the path appropriate to your own environment.

Background. A safe-bag attribute is metadata attached to an item inside a PKCS#12/PFX container; it does not change the certificate or private-key material. Recognized attributes include friendlyName, keyContainerName, keyName, and localKeyId. The encoding argument names the value's binary representation for binary attributes and is ignored for text-valued attributes such as friendlyName.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

set pfx [new_CkPfx]

#  The file path is relative to the application's current working directory.  An absolute path
#  may also be used.  Supply the path appropriate to your own environment.
#  The PFX password should come from a secure source rather than being hard-coded.
set password "myPfxPassword"
set success [CkPfx_LoadPfxFile $pfx "qa_data/identity.pfx" $password]
if {$success == 0} then {
    puts [CkPfx_lastErrorText $pfx]
    delete_CkPfx $pfx
    exit
}

#  Set a safe-bag attribute on an item inside the PFX.  Safe-bag attributes are metadata attached to
#  an item in the container; they do not change the certificate or key material itself.  The 1st
#  argument is 1 for a private key or 0 for a certificate, and the 2nd is the zero-based
#  index within that collection.
set bForPrivateKey 1

#  friendlyName is a text-valued attribute, so the encoding argument is ignored (pass an empty
#  string).  For binary attributes such as localKeyId, the encoding names the value's representation.
set success [CkPfx_SetSafeBagAttr $pfx $bForPrivateKey 0 "friendlyName" "My Identity" ""]
if {$success == 0} then {
    puts [CkPfx_lastErrorText $pfx]
    delete_CkPfx $pfx
    exit
}

puts "Safe-bag attribute set."

delete_CkPfx $pfx