PrivateKey Pascal Reference Documentation
PrivateKey
Current Version: 11.5.0
PrivateKey
Named load methods inspect the content and recognize supported unencrypted formats. Password-taking loaders also recognize encrypted PKCS #8 and unencrypted input. Use PKCS #8 for modern algorithm-independent interchange, encrypted PKCS #8 for password-protected storage, JWK for JOSE, and traditional PEM only when required by a legacy consumer. A successful load replaces the current key. A failed load leaves the object empty. Check Generate new keys with A private key does not contain a certificate or chain. Use For an extended overview, see PrivateKey Class Overview.Load, inspect, export, save, and convert one private key.
PrivateKey is a key-container class. It holds one current RSA, DSA, EC, or Ed25519 private key and provides
format conversion, persistence, JWK/XML access, raw EC and Ed25519 access, and public-key extraction. Cryptographic
operations such as signing, decryption, TLS authentication, and SSH authentication are performed by other Chilkat
classes that receive the loaded PrivateKey.
Content-based loading
Standard export choices
One-key state
KeyType and BitLength after loading when the expected algorithm matters.Independent public key
ToPublicKey creates an independent PublicKey that is unaffected when this object is reloaded with another key.Key generation
Rsa, Ecc, or EdDSA, which can place the generated key into a PrivateKey.Certificates are separate
Cert or Pfx when certificate association is required.aes256 and a strong password for stored key files, JWK for JWT/JWS/JWE workflows, and traditional RSA or EC PEM only when the receiving software requires it.
Create / Free
uses
Chilkat.PrivateKey;
var
obj: TPrivateKey;
begin
obj := TPrivateKey.Create;
try
if not obj.IsValid then
raise Exception.Create('Failed to create a TPrivateKey instance.');
// ... use obj ...
finally
obj.Free;
end;
end;
Allocates the underlying CkPrivateKey object and returns a new TPrivateKey instance. Simply adding Chilkat.PrivateKey to the unit's uses clause is enough to locate and bind to the Chilkat shared library (DLL / .so / .dylib) at runtime — no separate load step is required. Check obj.IsValid after calling Create; it is False if the underlying library could not be found/loaded or the object could not be allocated (for example, when unlicensed).
Every TPrivateKey created by calling Create should eventually be released by calling .Free (inherited from TObject). The destructor automatically disposes the underlying CkPrivateKey handle. A native (unmanaged) memory leak occurs if the object is never freed.
Properties
BitLength
Returns the nominal size of the loaded private key, in bits. The value is 0 when the object is empty. For RSA it is the modulus size; for DSA it is the size of p; for EC it is the named-curve field size; and for Ed25519 it is 256.
DebugLogFilePath
If set to a file path, this property logs the LastErrorText of each Chilkat method or property call to the specified file. This logging helps identify the context and history of Chilkat calls leading up to any crash or hang, aiding in debugging.
Enabling the VerboseLogging property provides more detailed information. This property is mainly used for debugging rare instances where a Chilkat method call causes a hang or crash, which should generally not happen.
Possible causes of hangs include:
- A timeout property set to 0, indicating an infinite timeout.
- A hang occurring within an event callback in the application code.
- An internal bug in the Chilkat code causing the hang.
KeyType
Identifies the algorithm of the currently loaded key. The value is one of empty, rsa, dsa, ecc, or ed25519. empty means that no usable private key is loaded.
PrivateKey object holds one current key. Loading another key replaces it; a failed load leaves the object empty.LastErrorHtml
Provides HTML-formatted information about the last called method or property. If a method call fails or behaves unexpectedly, check this property for details. Note that information is available regardless of the method call's success.
topLastErrorText
Provides plain text information about the last called method or property. If a method call fails or behaves unexpectedly, check this property for details. Note that information is available regardless of the method call's success.
LastErrorXml
Provides XML-formatted information about the last called method or property. If a method call fails or behaves unexpectedly, check this property for details. Note that information is available regardless of the method call's success.
topLastMethodSuccess
Indicates the success or failure of the most recent method call: True means success, False means failure. This property remains unchanged by property setters or getters. This method is present to address challenges in checking for null or Nothing returns in certain programming languages. Note: This property does not apply to methods that return integer values or to boolean-returning methods where the boolean does not indicate success or failure.
Pkcs8EncryptAlg
Controls the block cipher used by encrypted PKCS #8 export methods. Supported values are 3des, aes128, aes192, and aes256. Values are case-insensitive and are normalized to lowercase. The default is 3des. Assigning an empty or unrecognized value resets the property to 3des. All choices use CBC mode.
Encrypted PKCS #8 output uses PBES2 with PBKDF2. The generated parameters use an 8-byte salt, 2048 PBKDF2 iterations, and the default PBKDF2 PRF (HMAC-SHA-1). The selected cipher uses CBC mode with a newly generated IV.
aes256 for new output unless an older consumer requires 3DES. This property selects encryption parameters only; password quality remains essential.UncommonOptions
Provides a catch-all string for specialized compatibility options that are not exposed as ordinary properties. The default is the empty string, which is appropriate for normal use.
VerboseLogging
If set to True, then the contents of LastErrorText (or LastErrorXml, or LastErrorHtml) may contain more verbose information. The default value is False. Verbose logging should only be used for debugging. The potentially large quantity of logged information may adversely affect peformance.
Version
Methods
GetJwk
Exports the key as a compact JWK (JSON Web Key). Binary integers and byte strings use Base64url without padding.
| Key type | Members emitted |
|---|---|
| RSA | kty, n, e, d, p, q, dp, dq, qi |
| EC | kty, crv, x, y, d |
| Ed25519 | kty=OKP, crv=Ed25519, x, d, and use=sig |
kid, alg, key_ops, or a caller-supplied use, is not retained for re-export. The Ed25519 use=sig member is emitted by Chilkat.Returns True for success, False for failure.
GetJwkThumbprint
Computes the RFC 7638 thumbprint of the public portion of the loaded key using the hash algorithm named by hashAlg. Supported values include md5, sha1, sha256, sha384, and sha512. An unsupported name causes the method to fail. The returned digest is Base64url-encoded without padding.
kid, use, and alg are excluded, so the result matches the thumbprint of the corresponding PublicKey.sha256 for normal RFC 7638 interoperability. MD5 and SHA-1 are available for compatibility but should not be chosen for new security-sensitive identifiers.Returns True for success, False for failure.
GetPkcs1ENC
Exports the key as the traditional or preferred unencrypted DER representation and encodes the DER as text using the binary encoding named by encoding. The binary bytes are the same as returned by GetPkcs1.
| Key type | Returned representation |
|---|---|
| RSA | RSAPrivateKey DER from PKCS #1. |
| DSA | The traditional six-integer DSA private-key structure. |
| EC | ECPrivateKey DER from RFC 5915. |
| Ed25519 | PKCS #8 PrivateKeyInfo DER using the Ed25519 OID 1.3.101.112, because Ed25519 has no traditional PKCS #1 form. |
For RSA, the DER contains:
RSAPrivateKey ::= SEQUENCE {
version Version,
modulus INTEGER, -- n
publicExponent INTEGER, -- e
privateExponent INTEGER, -- d
prime1 INTEGER, -- p
prime2 INTEGER, -- q
exponent1 INTEGER, -- d mod (p-1)
exponent2 INTEGER, -- d mod (q-1)
coefficient INTEGER, -- (inverse of q) mod p
otherPrimeInfos OtherPrimeInfos OPTIONAL
}For EC, the traditional structure is:
ECPrivateKey ::= SEQUENCE {
version INTEGER { ecPrivkeyVer1(1) },
privateKey OCTET STRING,
parameters [0] ECParameters OPTIONAL,
publicKey [1] BIT STRING OPTIONAL
}encoding encoding name causes the method to fail; it does not silently select another encoding.Returns True for success, False for failure.
GetPkcs1Pem
Exports the key as unencrypted PEM, preferring the traditional algorithm-specific representation when one exists.
| Key type | PEM label | Body |
|---|---|---|
| RSA | RSA PRIVATE KEY | PKCS #1 DER |
| DSA | DSA PRIVATE KEY | Traditional DSA DER |
| EC | EC PRIVATE KEY | RFC 5915 DER |
| Ed25519 | PRIVATE KEY | PKCS #8 DER |
Returns True for success, False for failure.
GetPkcs8ENC
Exports the key as unencrypted PKCS #8 DER and encodes the DER as text using the binary encoding named by encoding. PKCS #8 is an algorithm-independent private-key container. Chilkat emits the classic version-0 PrivateKeyInfo structure, with the algorithm-specific private-key DER in an OCTET STRING.
PrivateKeyInfo ::= SEQUENCE {
version Version,
privateKeyAlgorithm AlgorithmIdentifier,
privateKey OCTET STRING,
attributes [0] IMPLICIT Attributes OPTIONAL
}encoding encoding name causes the method to fail; it does not silently select another encoding.Returns True for success, False for failure.
GetPkcs8EncryptedENC
const password: string): string;
Exports the key as password-protected PKCS #8 DER, then encodes the encrypted DER as text. encoding names the binary encoding and password supplies the password. The cipher is selected by Pkcs8EncryptAlg.
Encrypted PKCS #8 output uses PBES2 with PBKDF2. The generated parameters use an 8-byte salt, 2048 PBKDF2 iterations, and the default PBKDF2 PRF (HMAC-SHA-1). The selected cipher uses CBC mode with a newly generated IV.
encoding encoding name causes the method to fail.password is accepted but provides no meaningful password protection.Returns True for success, False for failure.
GetPkcs8EncryptedPem
Exports the key as password-protected PKCS #8 PEM using password as the password. The cipher is selected by Pkcs8EncryptAlg. The output uses:
-----BEGIN ENCRYPTED PRIVATE KEY----- ... -----END ENCRYPTED PRIVATE KEY-----
Encrypted PKCS #8 output uses PBES2 with PBKDF2. The generated parameters use an 8-byte salt, 2048 PBKDF2 iterations, and the default PBKDF2 PRF (HMAC-SHA-1). The selected cipher uses CBC mode with a newly generated IV.
password is accepted and still produces encrypted PKCS #8, but it provides no meaningful password protection.Returns True for success, False for failure.
GetPkcs8Pem
Exports the key as unencrypted PKCS #8 PEM. For RSA, EC, and Ed25519, the PEM armor is:
-----BEGIN PRIVATE KEY----- ... -----END PRIVATE KEY-----PKCS #8 is an algorithm-independent private-key container. Chilkat emits the classic version-0
PrivateKeyInfo structure, with the algorithm-specific private-key DER in an OCTET STRING.PrivateKeyInfo ::= SEQUENCE {
version Version,
privateKeyAlgorithm AlgorithmIdentifier,
privateKey OCTET STRING,
attributes [0] IMPLICIT Attributes OPTIONAL
}Returns True for success, False for failure.
GetPkcsBd
function GetPkcsBd(pkcs1: Boolean;
const password: string;
bd: TChilkatBase): Boolean;
Exports the key as DER and replaces the contents of the BinData in bd.
pkcs1 | password | Output |
|---|---|---|
True | Ignored for encryption. | RSA PKCS #1, traditional DSA, RFC 5915 EC, or PKCS #8 for Ed25519. |
False | Empty string. | Unencrypted PKCS #8 DER. |
False | Nonempty password. | Encrypted PKCS #8 DER using Pkcs8EncryptAlg. |
bd content. If the call fails, bd is cleared.pkcs1 is True, password does not encrypt the output. To obtain encrypted output, set pkcs1 to False and provide a nonempty password.Returns True for success, False for failure.
GetRawHex
function GetRawHex(pubKey: TChilkatBase): string;
Exports the raw private value as lowercase hexadecimal and replaces the contents of the StringBuilder in pubKey with the corresponding raw public key.
| Key type | Returned private value | Public value in pubKey |
|---|---|---|
| Ed25519 | The 32-byte seed accepted by LoadEd25519, as 64 hex characters. | The 32-byte public key, as 64 hex characters. |
| EC | The private scalar, padded to the curve size as needed. | The uncompressed point 04 || HEX(x) || HEX(y). |
pubKey is cleared.Returns True for success, False for failure.
GetXml
Exports the key in Chilkat-compatible XML. The XML is not encrypted. RSA and DSA components use ordinary Base64.
RSA keys use:
<RSAKeyValue> <Modulus>...</Modulus> <Exponent>...</Exponent> <D>...</D> <P>...</P> <Q>...</Q> <DP>...</DP> <DQ>...</DQ> <InverseQ>...</InverseQ> </RSAKeyValue>
DSA keys use:
<DSAKeyValue> <P>...</P> <Q>...</Q> <G>...</G> <Y>...</Y> <X>...</X> </DSAKeyValue>
EC keys place the named curve in the curve attribute and Base64-encode the RFC 5915 ECPrivateKey DER in the element content:
<ECCKeyValue curve="secp256r1">...</ECCKeyValue>
Ed25519 keys Base64-encode 64 bytes consisting of the 32-byte private seed followed by the 32-byte public key:
<Ed25519KeyValue>...</Ed25519KeyValue>
LoadXml, LoadXmlFile, or the general format-detection methods.Returns True for success, False for failure.
LoadAnyFormat
function LoadAnyFormat(privKeyData: TChilkatBase;
const password: string): Boolean;
Loads a private key from the data in privKeyData by inspecting its contents. Recognized representations include RSA PKCS #1 DER, traditional DSA and EC DER, PKCS #8 DER, encrypted PKCS #8, PEM, JWK, Chilkat-compatible XML, Microsoft PVK, and supported Ed25519 representations. password supplies the password when the detected representation is encrypted; otherwise it may be empty.
privKeyData contains the exact bytes to inspect. Textual PEM, JWK, and XML are detected from those bytes; a filename extension is not involved.Returns True for success, False for failure.
LoadAnyFormatFile
const password: string): Boolean;
Loads a private key from the file at path by inspecting its contents. Recognized representations include RSA PKCS #1 DER, traditional DSA and EC DER, PKCS #8 DER, encrypted PKCS #8, PEM, JWK, Chilkat-compatible XML, Microsoft PVK, and supported Ed25519 representations. password supplies the password when needed.
Returns True for success, False for failure.
LoadEd25519
const pubKey: string): Boolean;
Loads an Ed25519 key pair from raw hexadecimal values. privKey is the 32-byte Ed25519 private seed. pubKey is the 32-byte public key. Each nonempty value must contain exactly 64 hexadecimal digits. Uppercase hexadecimal and an optional 0x prefix are accepted; embedded whitespace is not accepted. pubKey may be empty, in which case Chilkat derives the public key from the seed.
pubKey is nonempty, Chilkat stores the supplied public value without checking that it corresponds to privKey. Pass an empty pubKey when the public key should be derived and guaranteed to match the private seed.Returns True for success, False for failure.
LoadEncryptedPem
const password: string): Boolean;
Loads a private key from the PEM text in pemStr. password supplies the password when the PEM is encrypted. The method accepts encrypted PKCS #8 PEM and also loads supported unencrypted PEM.
-----BEGIN ENCRYPTED PRIVATE KEY----- ... -----END ENCRYPTED PRIVATE KEY-----
Returns True for success, False for failure.
LoadEncryptedPemFile
const password: string): Boolean;
Loads a private key from the file at path, using password when the detected key is encrypted. The file may contain encrypted PKCS #8 PEM or another supported encrypted or unencrypted representation.
Returns True for success, False for failure.
LoadJwk
Loads a private key from the JWK JSON in jsonStr. Supported private JWK key types are RSA (kty=RSA), EC (kty=EC), and Ed25519 (kty=OKP, crv=Ed25519). An unsupported kty causes the method to fail.
PublicKey. This method is for JWKs that contain private key material.kid, use, alg, and key_ops may be present but is not retained by PrivateKey.Returns True for success, False for failure.
LoadPem
Loads a private key from the PEM text in str. This method has no password argument and therefore cannot load password-protected PEM. Use LoadEncryptedPem for encrypted input.
Returns True for success, False for failure.
LoadPemFile
Loads a private key from the file at path. This method has no password argument and therefore cannot load a password-protected key. Use LoadEncryptedPemFile or LoadAnyFormatFile when a password may be required.
Returns True for success, False for failure.
LoadPkcs1File
Loads a private key from the file at path. Despite the historical PKCS #1 name, the method examines the content and accepts supported unencrypted private-key representations.
Returns True for success, False for failure.
LoadPkcs8EncryptedFile
const password: string): Boolean;
Loads a private key from the file at path, using password when the detected key is encrypted. The method can load encrypted PKCS #8 DER or PEM and also supported unencrypted representations.
Returns True for success, False for failure.
LoadPkcs8File
Loads a private key from the file at path. Although named for unencrypted PKCS #8, the method examines the file content and accepts other supported unencrypted private-key representations.
Returns True for success, False for failure.
LoadPvkFile
const password: string): Boolean;
Loads a private key from the file at path, using password if the detected representation is encrypted. This Windows-only method supports Microsoft PVK and also participates in Chilkat private-key content auto-detection.
Returns True for success, False for failure.
LoadXml
Loads a private key from the XML text in xml. Supported Chilkat-compatible XML roots include RSAKeyValue, DSAKeyValue, ECCKeyValue, and Ed25519KeyValue.
Ed25519KeyValue content is ordinary Base64 for the 32-byte private seed followed by the 32-byte public key.Returns True for success, False for failure.
LoadXmlFile
Loads a private key from the file at path. Chilkat recognizes RSA, DSA, EC, and Ed25519 XML produced by GetXml, and also auto-detects other supported unencrypted private-key representations.
Returns True for success, False for failure.
SavePemFile
Saves the key at path as unencrypted PEM, preferring a traditional algorithm-specific representation when one exists. RSA uses RSA PRIVATE KEY, DSA uses DSA PRIVATE KEY, EC uses EC PRIVATE KEY, and Ed25519 uses the PKCS #8 PRIVATE KEY form.
SavePkcs8PemFile to always request the algorithm-independent PKCS #8 PRIVATE KEY form.Returns True for success, False for failure.
SavePkcs1File
Saves the key at path using the traditional or preferred unencrypted DER representation.
Returns True for success, False for failure.
SavePkcs8EncryptedFile
const path: string): Boolean;
Saves the key as password-protected PKCS #8 DER. password supplies the password and path is the destination path. The cipher is selected by Pkcs8EncryptAlg.
Encrypted PKCS #8 output uses PBES2 with PBKDF2. The generated parameters use an 8-byte salt, 2048 PBKDF2 iterations, and the default PBKDF2 PRF (HMAC-SHA-1). The selected cipher uses CBC mode with a newly generated IV.
password is accepted but provides no meaningful password protection.Returns True for success, False for failure.
SavePkcs8EncryptedPemFile
const path: string): Boolean;
Saves the key as password-protected PKCS #8 PEM. password supplies the password and path is the destination path. The file uses the ENCRYPTED PRIVATE KEY PEM label, and the cipher is selected by Pkcs8EncryptAlg.
Encrypted PKCS #8 output uses PBES2 with PBKDF2. The generated parameters use an 8-byte salt, 2048 PBKDF2 iterations, and the default PBKDF2 PRF (HMAC-SHA-1). The selected cipher uses CBC mode with a newly generated IV.
password is accepted but provides no meaningful password protection.Returns True for success, False for failure.
SavePkcs8File
Saves the key as unencrypted PKCS #8 DER at path. PKCS #8 is an algorithm-independent private-key container. Chilkat emits the classic version-0 PrivateKeyInfo structure, with the algorithm-specific private-key DER in an OCTET STRING.
PrivateKeyInfo ::= SEQUENCE {
version Version,
privateKeyAlgorithm AlgorithmIdentifier,
privateKey OCTET STRING,
attributes [0] IMPLICIT Attributes OPTIONAL
}path may be formatted as keychain:<label> to save the private key to the Apple Keychain.Returns True for success, False for failure.
SavePkcs8PemFile
Saves the key as unencrypted PKCS #8 PEM at path. The PEM label is PRIVATE KEY for RSA, EC, Ed25519, and other supported PKCS #8 key types.PKCS #8 is an algorithm-independent private-key container. Chilkat emits the classic version-0 PrivateKeyInfo structure, with the algorithm-specific private-key DER in an OCTET STRING.
PrivateKeyInfo ::= SEQUENCE {
version Version,
privateKeyAlgorithm AlgorithmIdentifier,
privateKey OCTET STRING,
attributes [0] IMPLICIT Attributes OPTIONAL
}Returns True for success, False for failure.
SaveXmlFile
Saves the key as unencrypted Chilkat-compatible XML at path. The XML representation is the same as returned by GetXml.
Returns True for success, False for failure.
ToPublicKey
function ToPublicKey(pubKey: TChilkatBase): Boolean;
Extracts the public portion of the loaded private key and stores an independent copy in the PublicKey supplied in pubKey. The resulting public key is unaffected if this PrivateKey is later reloaded with a different key.
pubKey is preserved.Returns True for success, False for failure.
UploadToCloud
// jsonOut is a TJsonObject object.
function UploadToCloud(jsonIn: TChilkatBase;
jsonOut: TChilkatBase): Boolean;
Uploads or imports the private key to a supported cloud key-management service. jsonIn supplies service-specific input parameters as a JsonObject, and jsonOut receives service-specific result information.
Returns True for success, False for failure.
topUploadToCloudAsync (1)
// jsonOut is a TJsonObject object.
// Return value is a TTask object.
function UploadToCloudAsync(jsonIn: TChilkatBase;
jsonOut: TChilkatBase): TChilkatBase;
Creates an asynchronous task to call the UploadToCloud method with the arguments provided.
Note: Async method event callbacks happen in the background thread. Accessing and updating UI elements existing in the main thread may require special considerations.
Returns nil on failure