Sample code for 30+ languages & platforms
Zig Requires Chilkat v11.0.0+

Generate a CSR with SAN (Subject Alternative Name) Extension

See more CSR Examples

Demonstrates how to generate a private key and a Certificate Signing Request (CSR) that includes the SAN extension.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // First generate an RSA private key.
    // (It is also possible to create CSRs based on ECDSA private keys..)
    const rsa = try chilkat.Rsa.init();
    defer rsa.deinit();

    // Generate a random 2048-bit RSA key.
    const priv_key = try chilkat.PrivateKey.init();
    defer priv_key.deinit();
    rsa.genKey(2048, priv_key) catch {
        std.debug.print("{s}\n", .{try rsa.getLastErrorText(alloc)});
        return;
    };

    // Create the CSR object and set properties.
    const csr = try chilkat.Csr.init();
    defer csr.deinit();

    // Specify the Common Name.
    csr.setCommonName("mysubdomain.mydomain.com");

    // Country Name (2 letter code)
    csr.setCountry("GB");

    // State or Province Name (full name)
    csr.setState("Yorks");

    // Locality Name (eg, city)
    csr.setLocality("York");

    // Organization Name (eg, company)
    csr.setCompany("Internet Widgits Pty Ltd");

    // Organizational Unit Name (eg, secion/division)
    csr.setCompanyDivision("IT");

    // Email address
    csr.setEmailAddress("support@mydomain.com");

    // Add Subject Alternative Names
    // (The AddSan method is added in Chilkat v9.5.0.84)
    // Call AddSan for each alternative name.
    try csr.addSan("dnsName", "mydomain.com");
    try csr.addSan("dnsName", "mysubdomain.mydomain.com");
    try csr.addSan("ipAddress", "192.168.0.123");

    // Create the CSR using the private key.
    const pem_str = csr.genCsrPem(alloc, priv_key) catch {
        std.debug.print("{s}\n", .{try csr.getLastErrorText(alloc)});
        return;
    };

    // Save the private key and CSR to a files.
    priv_key.savePkcs8EncryptedPemFile("password", "qa_output/privKey1.pem") catch {};

    const fac = try chilkat.FileAccess.init();
    defer fac.deinit();
    fac.writeEntireTextFile("qa_output/csr1.pem", pem_str, "utf-8", false) catch {};

    // Show the CSR.
    std.debug.print("{s}\n", .{pem_str});

    // Sample output:

    //     -----BEGIN CERTIFICATE REQUEST-----
    //     MIIC6jCCAdICAQAwgaQxITAfBgNVBAMMGG15c3ViZG9tYWluLm15ZG9tYWluLmNv
    //     bTELMAkGA1UEBhMCR0IxDjAMBgNVBAgMBVlvcmtzMQ0wCwYDVQQHDARZb3JrMSEw
    //     HwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQxCzAJBgNVBAsMAklUMSMw
    //     IQYJKoZIhvcNAQkBFhRzdXBwb3J0QG15ZG9tYWluLmNvbTCCASIwDQYJKoZIhvcN
    //     AQEBBQADggEPADCCAQoCggEBALnQ0un/wF8whk+gPuiAlf3qvx14jgAOV6Erm6EB
    //     H7WACPCpnKcm/8KP+7uoPiwRQaENhMeCgf45vcivl2p6aAn/spLXyEkXyw2d8wFb
    //     YYAGRkiz4Xf7ASJiKuwcOtORz+sSDzgtdfokHfXU1cYeFE2yQhSdLUY5fMn425+g
    //     KoEEsRSjSDe6AKru4+4iGNrLKd8pB9IA5/jOE139IkWlB9r5fEPD5bUTsgqXk9eb
    //     68O0gc712V2eZK07N24lDmFC4bIMTD4csDWocR5hFHXj7NX7c8sOBDcpEb9mPIk4
    //     elxubnhkfnjhOi4J3lDHcT/0ALnbLhf9LnaiKqs+5VcVZvECAwEAAaAAMA0GCSqG
    //     SIb3DQEBBQUAA4IBAQC0AETLIcP3foh5nbu2hVFS8uCUNZ5hEIR1eXmYZmZoBQq2
    //     26ZAoT4CZwixlggC+n7WvAXJ5Pzxpl4wLV4loTiQzaKPX1w0ERo5ZRwLy0n56oG2
    //     6QG+WTViT1C8rlgtVwkCFNOXr0kSSRs8FdaPllqKxK1hxYSL7zwNpumsk39F2cDt
    //     vhcekvH0V3BuGrQFm3dKN/0azW6GOod9+Vq4VzSyOe3kp15oxLBsZOFOu/REujcw
    //     Tzu2jt1asQKUm60CZ9wNHpYepR0Ww40uP1slbehEaFDa6V8b60/tlHHmBbJ4/fy5
    //     hJnYCvjzFz4O9VtT+JtP9ldRHWV3KpZ8ne3AjD+F
    //     -----END CERTIFICATE REQUEST-----
}