Sample code for 30+ languages & platforms
Zig

Load Particular CA Certs into a Java KeyStore

See more Java KeyStore (JKS) Examples

Opens a PEM file containing many CA root certificates, and creates a Java keystore containing a subset of the certificates.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    const jks = try chilkat.JavaKeyStore.init();
    defer jks.deinit();

    const troots = try chilkat.TrustedRoots.init();
    defer troots.deinit();

    // Load certificates from a file.
    troots.loadCaCertsPem("qa_data/curl_cacert.pem") catch {
        std.debug.print("{s}\n", .{try troots.getLastErrorText(alloc)});
        return;
    };

    const sb_dn = try chilkat.StringBuilder.init();
    defer sb_dn.deinit();
    const sb_alias = try chilkat.StringBuilder.init();
    defer sb_alias.deinit();
    const case_sensitive = false;

    var i: i32 = 0;
    const num_certs = troots.getNumCerts();
    var num_added: i32 = 0;
    while (i < num_certs) {
ERROR: Method not in the Zig package: TrustedRoots.GetCert
ERROR: Method not in the Zig package: TrustedRoots.GetCert
        const cacert = troots.ERROR();
        sb_dn.clear();
        sb_dn.append(try cacert.getSubjectDN(alloc)) catch {};
        if (sb_dn.contains("Entrust.net", case_sensitive)) {
            std.debug.print("{s}\n", .{try cacert.getSubjectDN(alloc)});

            // The alias is an arbitrary unique string for each cert in the JKS.
            sb_alias.clear();
            sb_alias.append("cacert_") catch {};
            sb_alias.appendInt(i + 1) catch {};
            jks.addTrustedCert(cacert, try sb_alias.getAsString(alloc)) catch {};
            num_added = num_added + 1;
        }

        i = i + 1;
    }

    // Verify the number of certs in the JKS equals the number we added.
    const num_jks_certs = jks.getNumTrustedCerts();
    std.debug.print("NumTrustedCerts = {d}\n", .{num_jks_certs});
    if (num_jks_certs != num_added) {
        std.debug.print("Something is amiss!\n", .{});
        return;
    }

    // Save the JKS.
    jks.toFile("myPassword", "qa_data/jks/entrust_caCerts.jks") catch {
        std.debug.print("{s}\n", .{try jks.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("Success.\n", .{});

    // The output of this program when tested was:

    // C=US, O=Entrust.net, OU=www.entrust.net/CPS incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Secure Server Certification Authority
    // O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
    // C=US, O="Entrust, Inc.", OU=www.entrust.net/CPS is incorporated by reference, OU="(c) 2006 Entrust, Inc.", CN=Entrust Root Certification Authority
    // NumTrustedCerts = 3
    // Success.
}