Sample code for 30+ languages & platforms
Xbase++

Export Selected PFX Contents as PEM

See more PFX/P12 Examples

Demonstrates Pfx.ToPemEx, which exports selected PFX contents as PEM-formatted text with control over which parts are included and how private keys are encrypted.

Background. Private keys are written in PKCS #8 form. Supported key-encryption algorithms include aes128, aes192, aes256, and 3des; leaving the algorithm empty produces unencrypted keys.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oPfx
LOCAL cPassword
LOCAL nBExtendedAttrs
LOCAL nBNoKeys
LOCAL nBNoCerts
LOCAL nBNoCaCerts
LOCAL cKeyPassword
LOCAL cPem

nSuccess := 0

oPfx := CreateObject("Chilkat.Pfx")

//  The file path is relative to the application's current working directory.  An absolute path
//  may also be used.  Supply the path appropriate to your own environment.
//  The PFX password should come from a secure source rather than being hard-coded.
cPassword := "myPfxPassword"
nSuccess := oPfx:LoadPfxFile("qa_data/identity.pfx", cPassword)
IF (nSuccess == 0)
    ? oPfx:LastErrorText
    oPfx:destroy()
    RETURN
ENDIF

//  Export selected PFX contents as PEM-formatted text.  The boolean arguments control what is
//  included: extended attributes, and whether to omit private keys, certificates, or CA certificates.
nBExtendedAttrs := 0
nBNoKeys := 0
nBNoCerts := 0
nBNoCaCerts := 0

//  Encrypt the exported private keys.  Supported algorithms include aes128, aes192, aes256, and 3des;
//  leave the algorithm empty for unencrypted keys.  The key password should come from a secure source.
cKeyPassword := "myKeyPassword"
cPem := oPfx:ToPemEx(nBExtendedAttrs, nBNoKeys, nBNoCerts, nBNoCaCerts, "aes256", cKeyPassword)
IF (oPfx:LastMethodSuccess == 0)
    ? oPfx:LastErrorText
    oPfx:destroy()
    RETURN
ENDIF

? cPem

oPfx:destroy()