Sample code for 30+ languages & platforms
Lianja

Working with PEM Encrypted Private Keys

See more PEM Examples

Demonstrates how to load and save PEM encrypted private keys.

Chilkat Lianja Downloads

Lianja
llSuccess = .F.

// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

llSuccess = .F.

loPem = createobject("CkPem")

lcPemPassword = "secret"

// To load a PEM file containing encrypted private keys, simply
// provide the password.
llSuccess = loPem.LoadPemFile("/Users/chilkat/testData/pem/pemContainingEncryptedPrivateKeys.pem",lcPemPassword)
if (llSuccess = .F.) then
    ? loPem.LastErrorText
    release loPem
    return
endif

loFac = createobject("CkFileAccess")
lcPemText = loFac.ReadEntireTextFile("/Users/chilkat/testData/pem/pemContainingEncryptedPrivateKeys.pem",lcPemPassword)

// To load a PEM from a string, call LoadPem instead of LoadPemFile:
llSuccess = loPem.LoadPem(lcPemText)
if (llSuccess = .F.) then
    ? loPem.LastErrorText
    release loPem
    release loFac
    return
endif

// A few notes:
// The PEM may contain both private keys and certificates (or anything else).
// The password is utilized for whatever content in the PEM is encrypted.  
// It is OK to have both encrypted and non-encrypted content within a given PEM.

// PEM private keys can be encrypted in different formats.  The LoadPem and LoadPemFile
// methods automatically handle the different formats.
// One format is PKCS8 and is indicated by this delimiter within the PEM:

// -----BEGIN ENCRYPTED PRIVATE KEY-----
// MIICoTAbBgkqhkiG9w0BBQMwDgQIfdD0zv24lgkCAggABIICgE0PdHJmRbNs6cBX
// ...

// Another format, we'll call "passphrase" looks like this in the PEM:
// -----BEGIN RSA PRIVATE KEY-----
// Proc-Type: 4,ENCRYPTED
// DEK-Info: DES-EDE3-CBC,A4215544D11C5D0C
// 
// paqy9XRexcSjurHfG0xhCaUD0HrvIdhuC0CbRxxxeMlkLaV6+uT80rBxt2AaibWG
// ...

// Show the bit length of each private key:

lnNumPrivateKeys = loPem.NumPrivateKeys
if (lnNumPrivateKeys = 0) then
    ? ("Error: Expected the PEM to contain private keys.")
    release loPem
    release loFac
    return
endif

loPrivKey = createobject("CkPrivateKey")
for i = 1 to lnNumPrivateKeys
    loPem.PrivateKeyAt(i - 1,loPrivKey)
    ? str(i) + ": " + str(loPrivKey.BitLength) + " bits"
next


release loPem
release loFac
release loPrivKey