Tcl
Tcl
Export Selected PFX Contents as PEM
See more PFX/P12 Examples
Demonstrates Pfx.ToPemEx, which exports selected PFX contents as PEM-formatted text with control over which parts are included and how private keys are encrypted.
Background. Private keys are written in PKCS #8 form. Supported key-encryption algorithms include
aes128, aes192, aes256, and 3des; leaving the algorithm empty produces unencrypted keys.Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
set pfx [new_CkPfx]
# The file path is relative to the application's current working directory. An absolute path
# may also be used. Supply the path appropriate to your own environment.
# The PFX password should come from a secure source rather than being hard-coded.
set password "myPfxPassword"
set success [CkPfx_LoadPfxFile $pfx "qa_data/identity.pfx" $password]
if {$success == 0} then {
puts [CkPfx_lastErrorText $pfx]
delete_CkPfx $pfx
exit
}
# Export selected PFX contents as PEM-formatted text. The boolean arguments control what is
# included: extended attributes, and whether to omit private keys, certificates, or CA certificates.
set bExtendedAttrs 0
set bNoKeys 0
set bNoCerts 0
set bNoCaCerts 0
# Encrypt the exported private keys. Supported algorithms include aes128, aes192, aes256, and 3des;
# leave the algorithm empty for unencrypted keys. The key password should come from a secure source.
set keyPassword "myKeyPassword"
set pem [CkPfx_toPemEx $pfx $bExtendedAttrs $bNoKeys $bNoCerts $bNoCaCerts "aes256" $keyPassword]
if {[CkPfx_get_LastMethodSuccess $pfx] == 0} then {
puts [CkPfx_lastErrorText $pfx]
delete_CkPfx $pfx
exit
}
puts "$pem"
delete_CkPfx $pfx