Sample code for 30+ languages & platforms
Tcl

Load an Encrypted Private Key from PEM Text

See more Private Key Examples

Demonstrates the Chilkat PrivateKey.LoadEncryptedPem method, which loads a private key from PEM text, using a password when the PEM is encrypted. The first argument is the PEM string and the second is the password. Unencrypted PEM is also accepted.

Background: An encrypted PEM protects the key material at rest — a stolen file is useless without the passphrase — which is why encrypted keys are preferred for anything shipped or stored. This loader supplies that passphrase to decrypt a BEGIN ENCRYPTED PRIVATE KEY block (and gracefully handles unencrypted PEM too), so it is a safe default when a PEM might be either. The password should come from a secure source, never a hard-coded literal.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

#  Demonstrates the PrivateKey.LoadEncryptedPem method, which loads a private key from PEM text.
#  The 1st argument is the PEM string and the 2nd is the password (used when the PEM is
#  encrypted).  Unencrypted PEM is also accepted.

set privKey [new_CkPrivateKey]

#  The PEM text of an encrypted private key.
set pemText "-----BEGIN ENCRYPTED PRIVATE KEY-----\nMIIFHzBJ...\n-----END ENCRYPTED PRIVATE KEY-----"

#  The key password is not hard-coded in a real application; obtain it from an interactive
#  prompt, environment variable, or a secrets vault.
set password "myKeyPassword"

set success [CkPrivateKey_LoadEncryptedPem $privKey $pemText $password]
if {$success == 0} then {
    puts [CkPrivateKey_lastErrorText $privKey]
    delete_CkPrivateKey $privKey
    exit
}

puts "Loaded a [CkPrivateKey_keyType $privKey] private key."

delete_CkPrivateKey $privKey