Sample code for 30+ languages & platforms
Xbase++ Requires Chilkat v11.0.0+

Get Certificates from .p12 / .pfx

See more PFX/P12 Examples

A PKCS12 (.p12 / .pfx) is a container for holding a certificate, its private key, and the certs in the chain of authentication up to and possibly including the root CA cert. A .p12 is not required to contain certain things. It will contain whatever the creator of the .p12 decided to include. It's possible to contain just a private key, just a cert, many certs without private keys, or many certs with many private keys. Usually, a .p12 contains one certificate, its associated private key, and certificates in the chain of authentication.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oPfx
LOCAL oCert
LOCAL nNumCerts
LOCAL i
LOCAL oIssuer

nSuccess := 0

oPfx := CreateObject("Chilkat.Pfx")

nSuccess := oPfx:LoadPfxFile("qa_data/pfx/test.pfx", "pfx_password")
IF (nSuccess == 0)
    ? oPfx:LastErrorText
    oPfx:destroy()
    RETURN
ENDIF

//  Iterate over the certs contained in the PFX
oCert := CreateObject("Chilkat.Cert")
nNumCerts := oPfx:NumCerts
i := 0
DO WHILE i < nNumCerts

    oPfx:CertAt(i, oCert)

    ? "--- " + Str(i) + " ---"
    ? oCert:SubjectDN
    //  Is this a root cert, or self-signed?
    ? "Root: " + Str(oCert:IsRoot)
    ? "Self-Signed: " + Str(oCert:SelfSigned)

    //  If this certificate is not the root (self-signed), then get the issuer.
    //  If the issuing certificate is contained in the PFX, then it will be found here..
    IF (oCert:SelfSigned != 1)
        oIssuer := oCert:FindIssuer()
        IF (oCert:LastMethodSuccess == 0)
            ? "Issuer not found."
        ELSE
            ? "Issuer: " + oIssuer:SubjectDN
            oIssuer:destroy()
        ENDIF

    ENDIF

    i := i + 1
ENDDO

//  Usually, the user certificate is at index 0, its issuer is at index 1, etc. until we get to the root certificate.

oPfx:destroy()
oCert:destroy()