Sample code for 30+ languages & platforms
Zig

Export Selected PFX Contents as PEM

See more PFX/P12 Examples

Demonstrates Pfx.ToPemEx, which exports selected PFX contents as PEM-formatted text with control over which parts are included and how private keys are encrypted.

Background. Private keys are written in PKCS #8 form. Supported key-encryption algorithms include aes128, aes192, aes256, and 3des; leaving the algorithm empty produces unencrypted keys.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    const pfx = try chilkat.Pfx.init();
    defer pfx.deinit();

    // The file path is relative to the application's current working directory.  An absolute path
    // may also be used.  Supply the path appropriate to your own environment.
    // The PFX password should come from a secure source rather than being hard-coded.
    const password = "myPfxPassword";
    pfx.loadPfxFile("qa_data/identity.pfx", password) catch {
        std.debug.print("{s}\n", .{try pfx.getLastErrorText(alloc)});
        return;
    };

    // Export selected PFX contents as PEM-formatted text.  The boolean arguments control what is
    // included: extended attributes, and whether to omit private keys, certificates, or CA certificates.
    const b_extended_attrs = false;
    const b_no_keys = false;
    const b_no_certs = false;
    const b_no_ca_certs = false;

    // Encrypt the exported private keys.  Supported algorithms include aes128, aes192, aes256, and 3des;
    // leave the algorithm empty for unencrypted keys.  The key password should come from a secure source.
    const key_password = "myKeyPassword";
    const pem = pfx.toPemEx(alloc, b_extended_attrs, b_no_keys, b_no_certs, b_no_ca_certs, "aes256", key_password) catch {
        std.debug.print("{s}\n", .{try pfx.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("{s}\n", .{pem});
}