Tcl
Tcl
Load an Encrypted Private Key from PEM Text
See more Private Key Examples
Demonstrates the Chilkat PrivateKey.LoadEncryptedPem method, which loads a private key from PEM text, using a password when the PEM is encrypted. The first argument is the PEM string and the second is the password. Unencrypted PEM is also accepted.
Background: An encrypted PEM protects the key material at rest — a stolen file is useless without the passphrase — which is why encrypted keys are preferred for anything shipped or stored. This loader supplies that passphrase to decrypt a
BEGIN ENCRYPTED PRIVATE KEY block (and gracefully handles unencrypted PEM too), so it is a safe default when a PEM might be either. The password should come from a secure source, never a hard-coded literal.Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
# Demonstrates the PrivateKey.LoadEncryptedPem method, which loads a private key from PEM text.
# The 1st argument is the PEM string and the 2nd is the password (used when the PEM is
# encrypted). Unencrypted PEM is also accepted.
set privKey [new_CkPrivateKey]
# The PEM text of an encrypted private key.
set pemText "-----BEGIN ENCRYPTED PRIVATE KEY-----\nMIIFHzBJ...\n-----END ENCRYPTED PRIVATE KEY-----"
# The key password is not hard-coded in a real application; obtain it from an interactive
# prompt, environment variable, or a secrets vault.
set password "myKeyPassword"
set success [CkPrivateKey_LoadEncryptedPem $privKey $pemText $password]
if {$success == 0} then {
puts [CkPrivateKey_lastErrorText $privKey]
delete_CkPrivateKey $privKey
exit
}
puts "Loaded a [CkPrivateKey_keyType $privKey] private key."
delete_CkPrivateKey $privKey