Unicode C
Unicode C
Export Selected PFX Contents as PEM
See more PFX/P12 Examples
Demonstrates Pfx.ToPemEx, which exports selected PFX contents as PEM-formatted text with control over which parts are included and how private keys are encrypted.
Background. Private keys are written in PKCS #8 form. Supported key-encryption algorithms include
aes128, aes192, aes256, and 3des; leaving the algorithm empty produces unencrypted keys.Chilkat Unicode C Downloads
#include <C_CkPfxW.h>
void ChilkatSample(void)
{
BOOL success;
HCkPfxW pfx;
const wchar_t *password;
BOOL bExtendedAttrs;
BOOL bNoKeys;
BOOL bNoCerts;
BOOL bNoCaCerts;
const wchar_t *keyPassword;
const wchar_t *pem;
success = FALSE;
pfx = CkPfxW_Create();
// The file path is relative to the application's current working directory. An absolute path
// may also be used. Supply the path appropriate to your own environment.
// The PFX password should come from a secure source rather than being hard-coded.
password = L"myPfxPassword";
success = CkPfxW_LoadPfxFile(pfx,L"qa_data/identity.pfx",password);
if (success == FALSE) {
wprintf(L"%s\n",CkPfxW_lastErrorText(pfx));
CkPfxW_Dispose(pfx);
return;
}
// Export selected PFX contents as PEM-formatted text. The boolean arguments control what is
// included: extended attributes, and whether to omit private keys, certificates, or CA certificates.
bExtendedAttrs = FALSE;
bNoKeys = FALSE;
bNoCerts = FALSE;
bNoCaCerts = FALSE;
// Encrypt the exported private keys. Supported algorithms include aes128, aes192, aes256, and 3des;
// leave the algorithm empty for unencrypted keys. The key password should come from a secure source.
keyPassword = L"myKeyPassword";
pem = CkPfxW_toPemEx(pfx,bExtendedAttrs,bNoKeys,bNoCerts,bNoCaCerts,L"aes256",keyPassword);
if (CkPfxW_getLastMethodSuccess(pfx) == FALSE) {
wprintf(L"%s\n",CkPfxW_lastErrorText(pfx));
CkPfxW_Dispose(pfx);
return;
}
wprintf(L"%s\n",pem);
CkPfxW_Dispose(pfx);
}