Sample code for 30+ languages & platforms
Tcl

Convert Cert + Key to PEM and PFX

See more Certificates Examples

This example is based on the following question from a Chilkat customer:

We receive 2 files :

    MyCertificate.p7b
    MyCertificate-privatekey.pkey

We have to transform these certificate like this:

First convert it to PEM like this:

openssl pkcs7 -in MyCertificate.p7b -inform DER -out MyCertificate.pem -print_certs

Now we get MyCertificate.pem

Last step, we need to convert it to pfx file:

openssl pkcs12 -export -inkey moncertificat-privatekey.pkey  -in  moncertificat.pem -out moncertificat.pfx

Is there a way to make all these steps with Chilkat ?

I will be nice to include this directly in our software instead of askig the user to do it manualy.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

set cert [new_CkCert]

set privKey [new_CkPrivateKey]

# Load any type of certificate (.cer, .p7b, .pem, etc.) by calling LoadFromFile.
set success [CkCert_LoadFromFile $cert "qa_data/certs/sample_cert_a.cer"]
if {$success != 1} then {
    puts [CkCert_lastErrorText $cert]
    delete_CkCert $cert
    delete_CkPrivateKey $privKey
    exit
}

# Load the private key.
# (The various privKey methods that load from a file will automatically detect
# the format.  It doesn't actually matter if you try to load a non-PKCS8 format private key
# by calling LoadPkcs8EncryptedFile -- internally Chilkat will detect the format and will load
# based on what it finds.)
set success [CkPrivateKey_LoadPkcs8EncryptedFile $privKey "qa_data/certs/sample_key_a.pkcs8" "password"]
if {$success != 1} then {
    puts [CkPrivateKey_lastErrorText $privKey]
    delete_CkCert $cert
    delete_CkPrivateKey $privKey
    exit
}

# Write the cert as PEM.
set success [CkCert_ExportCertPemFile $cert "qa_output/cert.pem"]

# Or get the PEM string directly...
puts [CkCert_exportCertPem $cert]

# Associate the private key with the cert object.
set success [CkCert_SetPrivateKey $cert $privKey]
if {$success != 1} then {
    puts [CkCert_lastErrorText $cert]
    delete_CkCert $cert
    delete_CkPrivateKey $privKey
    exit
}

# Write the cert + private key to a .pfx file.
set success [CkCert_ExportToPfxFile $cert "qa_data/myPfx.pfx" "password" 1]
if {$success != 1} then {
    puts [CkCert_lastErrorText $cert]
    delete_CkCert $cert
    delete_CkPrivateKey $privKey
    exit
}

puts "Success."

delete_CkCert $cert
delete_CkPrivateKey $privKey