Zig
Zig
Export a Private Key as DER into a BinData
See more Private Key Examples
Demonstrates the Chilkat PrivateKey.GetPkcsBd method, which exports the key as DER into a BinData. The first argument selects PKCS #1 (true) versus PKCS #8 (false), the second is the password (empty for unencrypted), and the third is the BinData that receives the bytes.
Note: The file paths are relative to the application's current working directory. Absolute paths may also be used. Supply the paths appropriate to your own environment.
Background: This is the in-memory binary export — the raw DER bytes land in a
BinData ready to hash, encrypt, or hand to another API without a temporary file. One method covers several cases: the boolean picks the traditional (PKCS #1) versus modern (PKCS #8) structure, and a nonempty password produces an encrypted PKCS #8 export (with the cipher from Pkcs8EncryptAlg). Source any password securely.Chilkat Zig Downloads
const std = @import("std");
const chilkat = @import("chilkat");
pub fn main(init: std.process.Init) !void {
const alloc = init.arena.allocator();
// Load a private key to export.
const priv_key = try chilkat.PrivateKey.init();
defer priv_key.deinit();
priv_key.loadPemFile("qa_data/private.pem") catch {
std.debug.print("{s}\n", .{try priv_key.getLastErrorText(alloc)});
return;
};
// The key password is not hard-coded in a real application; obtain it from an interactive
// prompt, environment variable, or a secrets vault.
const password = "myKeyPassword";
// Export the key as DER into a BinData. The 1st argument selects PKCS #1 (true) versus PKCS #8
// (false); the 2nd is the password (empty string for an unencrypted export); the 3rd is the
// BinData that receives the DER bytes.
const use_pkcs1 = false;
const bd = try chilkat.BinData.init();
defer bd.deinit();
priv_key.getPkcsBd(use_pkcs1, password, bd) catch {
std.debug.print("{s}\n", .{try priv_key.getLastErrorText(alloc)});
return;
};
std.debug.print("Exported {d} DER bytes.\n", .{bd.getNumBytes()});
}