Sample code for 30+ languages & platforms
Zig Requires Chilkat v11.0.0+

Get Certificates from .p12 / .pfx

See more PFX/P12 Examples

A PKCS12 (.p12 / .pfx) is a container for holding a certificate, its private key, and the certs in the chain of authentication up to and possibly including the root CA cert. A .p12 is not required to contain certain things. It will contain whatever the creator of the .p12 decided to include. It's possible to contain just a private key, just a cert, many certs without private keys, or many certs with many private keys. Usually, a .p12 contains one certificate, its associated private key, and certificates in the chain of authentication.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    const pfx = try chilkat.Pfx.init();
    defer pfx.deinit();

    pfx.loadPfxFile("qa_data/pfx/test.pfx", "pfx_password") catch {
        std.debug.print("{s}\n", .{try pfx.getLastErrorText(alloc)});
        return;
    };

    // Iterate over the certs contained in the PFX
    const cert = try chilkat.Cert.init();
    defer cert.deinit();
    const num_certs = pfx.getNumCerts();
    var i: i32 = 0;
    while (i < num_certs) {
        pfx.certAt(i, cert) catch {};

        std.debug.print("--- {d} ---\n", .{i});
        std.debug.print("{s}\n", .{try cert.getSubjectDN(alloc)});
        // Is this a root cert, or self-signed?
        std.debug.print("Root: {}\n", .{cert.getIsRoot()});
        std.debug.print("Self-Signed: {}\n", .{cert.getSelfSigned()});

        // If this certificate is not the root (self-signed), then get the issuer.
        // If the issuing certificate is contained in the PFX, then it will be found here..
        if (!cert.getSelfSigned()) {
            const issuer = try cert.findIssuer();
            defer issuer.deinit();
            if (!cert.getLastMethodSuccess()) {
                std.debug.print("Issuer not found.\n", .{});
            } else {
                std.debug.print("Issuer: {s}\n", .{try issuer.getSubjectDN(alloc)});
            }
        }

        i = i + 1;
    }

    // Usually, the user certificate is at index 0, its issuer is at index 1, etc. until we get to the root certificate.
}