Sample code for 30+ languages & platforms
Zig

Convert Let's Encrypt PEM Files to a PFX

See more PFX/P12 Examples

Demonstrates how to convert the .pem files provided by Let's Encrypt to a single PFX.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example assumes the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // Let's Encrypt provides four .pem files
    // 1. fullchain.pem
    // 2. privkey.pem
    // 3. cert.pem
    // 4. chain.pem

    // The cert.pem and chain.pem are redundant.
    // The fullchain.pem is composed of the cert.pem and chain.pem.

    // To convert the PEM's to a single .pfx, we don't need the redundant data.
    // The privkey.pem and fullchain.pem provide the required data.
    // We can ignore cert.pem and chain.pem (because those certs are already found in fullchain.pem).

    // We need a single .pem file that contains both the private key, the cert,
    // and the certs in the chain of authentication.
    // Let's combine priveky.pem and fullchain.pem into a single .pem

    const sb_pem = try chilkat.StringBuilder.init();
    defer sb_pem.deinit();
    sb_pem.loadFile("qa_data/pem/lets_encrypt/privkey.pem", "utf-8") catch {
        std.debug.print("Failed to load privkey.pem\n", .{});
        return;
    };

    // To be safe, append a blank line..
    sb_pem.appendLine("", false) catch {};

    const sb_full_chain_pem = try chilkat.StringBuilder.init();
    defer sb_full_chain_pem.deinit();
    sb_full_chain_pem.loadFile("qa_data/pem/lets_encrypt/fullchain.pem", "utf-8") catch {
        std.debug.print("Failed to load fullchain.pem\n", .{});
        return;
    };

    // Append the full cert chain PEM to the private key PEM.
    sb_pem.appendSb(sb_full_chain_pem) catch {};

    // Load the combined PEM into a Chilkat PFX object.
    const pfx = try chilkat.Pfx.init();
    defer pfx.deinit();
    pfx.loadPem(try sb_pem.getAsString(alloc), "no password required") catch {
        std.debug.print("{s}\n", .{try pfx.getLastErrorText(alloc)});
        return;
    };

    // Write the PFX w/ a password.
    const pfx_password = "secret";
    pfx.toFile(pfx_password, "qa_output/sample.pfx") catch {
        std.debug.print("{s}\n", .{try pfx.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("Success!\n", .{});
}