Sample code for 30+ languages & platforms
Perl

Get Certificates from .p12 / .pfx

See more PFX/P12 Examples

A PKCS12 (.p12 / .pfx) is a container for holding a certificate, its private key, and the certs in the chain of authentication up to and possibly including the root CA cert. A .p12 is not required to contain certain things. It will contain whatever the creator of the .p12 decided to include. It's possible to contain just a private key, just a cert, many certs without private keys, or many certs with many private keys. Usually, a .p12 contains one certificate, its associated private key, and certificates in the chain of authentication.

Chilkat Perl Downloads

Perl
use chilkat();

$success = 0;

$pfx = chilkat::CkPfx->new();

$success = $pfx->LoadPfxFile("qa_data/pfx/test.pfx","pfx_password");
if ($success == 0) {
    print $pfx->lastErrorText() . "\r\n";
    exit;
}

# Iterate over the certs contained in the PFX
$cert = chilkat::CkCert->new();
$numCerts = $pfx->get_NumCerts();
$i = 0;
while ($i < $numCerts) {

    $pfx->CertAt($i,$cert);

    print "--- " . $i . " ---" . "\r\n";
    print $cert->subjectDN() . "\r\n";
    # Is this a root cert, or self-signed?
    print "Root: " . $cert->get_IsRoot() . "\r\n";
    print "Self-Signed: " . $cert->get_SelfSigned() . "\r\n";

    # If this certificate is not the root (self-signed), then get the issuer.
    # If the issuing certificate is contained in the PFX, then it will be found here..
    if ($cert->get_SelfSigned() != 1) {
        # issuer is a Cert
        $issuer = $cert->FindIssuer();
        if ($cert->get_LastMethodSuccess() == 0) {
            print "Issuer not found." . "\r\n";
        }
        else {
            print "Issuer: " . $issuer->subjectDN() . "\r\n";

        }

    }

    $i = $i + 1;
}

# Usually, the user certificate is at index 0, its issuer is at index 1, etc. until we get to the root certificate.