Tcl
Tcl
Convert a PuTTY Private Key (.ppk) to OpenSSH (.pem)
See more SSH Examples
Demonstrates converting a PuTTY format private key to OpenSSH format. The .ppk is imported with FromPuttyPrivateKey and re-exported with ToOpenSshPrivateKey, both unencrypted and encrypted.
Note: The file paths are relative to the application's current working directory. Supply the paths to your own files.
Background: PuTTY and OpenSSH store the same underlying key material in different container formats, so converting between them is a re-encoding rather than a new key — the corresponding public key, and therefore the server-side
authorized_keys entry, is unchanged. This matters when moving between Windows tooling built around PuTTY and Unix tooling that expects PEM. Note that the Password property serves double duty: it decrypts the key on import and encrypts it on export, so set it appropriately for each step.Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
# Demonstrates converting a PuTTY format private key (.ppk) to OpenSSH (.pem) format.
set key [new_CkSshKey]
# Set the password before importing an encrypted PuTTY key. If the key is not encrypted it
# makes no difference whether Password is set. This should come from a secure source rather
# than being hard-coded.
CkSshKey_put_Password $key "myKeyPassword"
# LoadText is a convenience method that reads any text file into a string. It does not itself
# load the key.
set keyStr [CkSshKey_loadText $key "qa_data/putty_private_key.ppk"]
if {[CkSshKey_get_LastMethodSuccess $key] == 0} then {
puts [CkSshKey_lastErrorText $key]
delete_CkSshKey $key
exit
}
set success [CkSshKey_FromPuttyPrivateKey $key $keyStr]
if {$success == 0} then {
puts [CkSshKey_lastErrorText $key]
delete_CkSshKey $key
exit
}
# Export to an unencrypted OpenSSH key.
set bEncrypt 0
set unencryptedKeyStr [CkSshKey_toOpenSshPrivateKey $key $bEncrypt]
if {[CkSshKey_get_LastMethodSuccess $key] == 0} then {
puts [CkSshKey_lastErrorText $key]
delete_CkSshKey $key
exit
}
set success [CkSshKey_SaveText $key $unencryptedKeyStr "qa_output/unencrypted_openssh.pem"]
if {$success == 0} then {
puts [CkSshKey_lastErrorText $key]
delete_CkSshKey $key
exit
}
# Export to an encrypted OpenSSH key. The Password property supplies the passphrase used to
# encrypt the output.
set bEncrypt 1
CkSshKey_put_Password $key "myExportPassword"
set encryptedKeyStr [CkSshKey_toOpenSshPrivateKey $key $bEncrypt]
if {[CkSshKey_get_LastMethodSuccess $key] == 0} then {
puts [CkSshKey_lastErrorText $key]
delete_CkSshKey $key
exit
}
set success [CkSshKey_SaveText $key $encryptedKeyStr "qa_output/encrypted_openssh.pem"]
if {$success == 0} then {
puts [CkSshKey_lastErrorText $key]
delete_CkSshKey $key
exit
}
puts "Done!"
delete_CkSshKey $key