Sample code for 30+ languages & platforms
Zig Requires Chilkat v11.0.0+

Working with PEM Encrypted Private Keys

See more PEM Examples

Demonstrates how to load and save PEM encrypted private keys.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    var success: bool = false;

    // This example assumes the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    success = false;

    const pem = try chilkat.Pem.init();
    defer pem.deinit();

    const pem_password = "secret";

    // To load a PEM file containing encrypted private keys, simply
    // provide the password.
    pem.loadPemFile("/Users/chilkat/testData/pem/pemContainingEncryptedPrivateKeys.pem", pem_password) catch {
        std.debug.print("{s}\n", .{try pem.getLastErrorText(alloc)});
        return;
    };

    const fac = try chilkat.FileAccess.init();
    defer fac.deinit();
    const pem_text = try fac.readEntireTextFile(alloc, "/Users/chilkat/testData/pem/pemContainingEncryptedPrivateKeys.pem", "utf-8");

    // To load a PEM from a string, call LoadPem instead of LoadPemFile:
    pem.loadPem(pem_text, pem_password) catch {
        std.debug.print("{s}\n", .{try pem.getLastErrorText(alloc)});
        return;
    };

    // A few notes:
    // The PEM may contain both private keys and certificates (or anything else).
    // The password is utilized for whatever content in the PEM is encrypted.
    // It is OK to have both encrypted and non-encrypted content within a given PEM.

    // PEM private keys can be encrypted in different formats.  The LoadPem and LoadPemFile
    // methods automatically handle the different formats.
    // One format is PKCS8 and is indicated by this delimiter within the PEM:

    // -----BEGIN ENCRYPTED PRIVATE KEY-----
    // MIICoTAbBgkqhkiG9w0BBQMwDgQIfdD0zv24lgkCAggABIICgE0PdHJmRbNs6cBX
    // ...

    // Another format, we'll call "passphrase" looks like this in the PEM:
    // -----BEGIN RSA PRIVATE KEY-----
    // Proc-Type: 4,ENCRYPTED
    // DEK-Info: DES-EDE3-CBC,A4215544D11C5D0C
    //
    // paqy9XRexcSjurHfG0xhCaUD0HrvIdhuC0CbRxxxeMlkLaV6+uT80rBxt2AaibWG
    // ...

    // Show the bit length of each private key:
    var i: i32 = 0;
    const num_private_keys = pem.getNumPrivateKeys();
    if (num_private_keys == 0) {
        std.debug.print("{s}\n", .{("Error: Expected the PEM to contain private keys.")});
        return;
    }

    const priv_key = try chilkat.PrivateKey.init();
    defer priv_key.deinit();
    i = 1;
    while (i <= num_private_keys) : (i += 1) {
        pem.privateKeyAt(i - 1, priv_key) catch {};
        std.debug.print("{d}: {d} bits\n", .{ i, priv_key.getBitLength() });
    }
}