Sample code for 30+ languages & platforms
Dart Requires Chilkat v11.0.0+

Working with PEM Encrypted Private Keys

See more PEM Examples

Demonstrates how to load and save PEM encrypted private keys.

Chilkat Dart Downloads

Dart
import 'package:chilkat/chilkat.dart';

void main() {
  // This example assumes the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  final pem = CkPem();

  final pemPassword = 'secret';

  // To load a PEM file containing encrypted private keys, simply
  // provide the password.
  try {
    pem.loadPemFile('/Users/chilkat/testData/pem/pemContainingEncryptedPrivateKeys.pem', pemPassword);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  final fac = CkFileAccess();
  final pemText = fac.readEntireTextFile('/Users/chilkat/testData/pem/pemContainingEncryptedPrivateKeys.pem', 'utf-8');

  // To load a PEM from a string, call LoadPem instead of LoadPemFile:
  try {
    pem.loadPem(pemText, pemPassword);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // A few notes:
  // The PEM may contain both private keys and certificates (or anything else).
  // The password is utilized for whatever content in the PEM is encrypted.  
  // It is OK to have both encrypted and non-encrypted content within a given PEM.

  // PEM private keys can be encrypted in different formats.  The LoadPem and LoadPemFile
  // methods automatically handle the different formats.
  // One format is PKCS8 and is indicated by this delimiter within the PEM:

  // -----BEGIN ENCRYPTED PRIVATE KEY-----
  // MIICoTAbBgkqhkiG9w0BBQMwDgQIfdD0zv24lgkCAggABIICgE0PdHJmRbNs6cBX
  // ...

  // Another format, we'll call "passphrase" looks like this in the PEM:
  // -----BEGIN RSA PRIVATE KEY-----
  // Proc-Type: 4,ENCRYPTED
  // DEK-Info: DES-EDE3-CBC,A4215544D11C5D0C
  // 
  // paqy9XRexcSjurHfG0xhCaUD0HrvIdhuC0CbRxxxeMlkLaV6+uT80rBxt2AaibWG
  // ...

  // Show the bit length of each private key:
  final numPrivateKeys = pem.numPrivateKeys;
  if (numPrivateKeys == 0) {
    print(('Error: Expected the PEM to contain private keys.'));
    return;
  }

  final privKey = CkPrivateKey();
  for (var i = 1; i <= numPrivateKeys; i++) {
    pem.privateKeyAt(i - 1, privKey);
    print('$i: ${privKey.bitLength} bits');
  }
}