Sample code for 30+ languages & platforms
Xbase++

Load Particular CA Certs into a Java KeyStore

See more Java KeyStore (JKS) Examples

Opens a PEM file containing many CA root certificates, and creates a Java keystore containing a subset of the certificates.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oJks
LOCAL oTroots
LOCAL oSbDn
LOCAL oSbAlias
LOCAL nCaseSensitive
LOCAL i
LOCAL nNumCerts
LOCAL nNumAdded
LOCAL oCacert
LOCAL nNumJksCerts

nSuccess := 0

//  This requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

oJks := CreateObject("Chilkat.JavaKeyStore")

oTroots := CreateObject("Chilkat.TrustedRoots")

//  Load certificates from a file.
nSuccess := oTroots:LoadCaCertsPem("qa_data/curl_cacert.pem")
IF (nSuccess != 1)
    ? oTroots:LastErrorText
    oJks:destroy()
    oTroots:destroy()
    RETURN
ENDIF

oSbDn := CreateObject("Chilkat.StringBuilder")
oSbAlias := CreateObject("Chilkat.StringBuilder")
nCaseSensitive := 0

i := 0
nNumCerts := oTroots:NumCerts
nNumAdded := 0
DO WHILE (i < nNumCerts)
    oCacert := oTroots:GetCert(i)
    oSbDn:Clear()
    oSbDn:Append(oCacert:SubjectDN)
    IF (oSbDn:Contains("Entrust.net", nCaseSensitive) == 1)
        ? oCacert:SubjectDN

        //  The alias is an arbitrary unique string for each cert in the JKS.
        oSbAlias:Clear()
        oSbAlias:Append("cacert_")
        oSbAlias:AppendInt(i + 1)
        oJks:AddTrustedCert(oCacert, oSbAlias:GetAsString())
        nNumAdded := nNumAdded + 1
    ENDIF

    oCacert:destroy()
    i := i + 1
ENDDO

//  Verify the number of certs in the JKS equals the number we added.
nNumJksCerts := oJks:NumTrustedCerts
? "NumTrustedCerts = " + Str(nNumJksCerts)
IF (nNumJksCerts != nNumAdded)
    ? "Something is amiss!"
    oJks:destroy()
    oTroots:destroy()
    oSbDn:destroy()
    oSbAlias:destroy()
    RETURN
ENDIF

//  Save the JKS.
nSuccess := oJks:ToFile("myPassword", "qa_data/jks/entrust_caCerts.jks")
IF (nSuccess != 1)
    ? oJks:LastErrorText
    oJks:destroy()
    oTroots:destroy()
    oSbDn:destroy()
    oSbAlias:destroy()
    RETURN
ENDIF

? "Success."

//  The output of this program when tested was:

//  C=US, O=Entrust.net, OU=www.entrust.net/CPS incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Secure Server Certification Authority
//  O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
//  C=US, O="Entrust, Inc.", OU=www.entrust.net/CPS is incorporated by reference, OU="(c) 2006 Entrust, Inc.", CN=Entrust Root Certification Authority
//  NumTrustedCerts = 3
//  Success.

oJks:destroy()
oTroots:destroy()
oSbDn:destroy()
oSbAlias:destroy()