alanj853
Hi,
I am working on a project where I am trying to use a PKCS12 keystore with a password for storing my Web Certificate and Private Key files in for my Phoenix Web Server, as opposed to the passing in the real file paths for the :certfile and :keyfile options in the https options Phoenix Endpoint config.
The reason for this security, where we don’t want to keep the real files in the open on our filesystem.
Has anyone tried this before? I haven’t been able to find much support online for doing this.
Thanks in advance for any help.
Trending in Questions
I having some trouble figuring out if I have set myself too strict of standards for my production server. Currently I can handle 75% of r...
New
Hello,
I’m trying to build a basic Phoenix web-app, and I’d like to use Tailwind.
However, when I launch mix phx.server, I get an error...
New
I really like the adapter patterns that ecto, nebulex, waffle, etc. use and would love find something similar for a key management servic...
New
I’m working on a small exercise involving update_in/3, and I came up with this solution:
data = %{
name: "Periodic Table",
category:...
New
I’ve got trouble wrapping my head around the order in which functions are called in this snippet (from Phoenix’s authentication):
toke...
New
Hello folks!
So at work, we are seeing some situations where we have to define some “fixed” strings that are used across the codebase in...
New
Is there any way to avoid the Hologram compiler running when using iex? It seems like the front-end code could potentially be disregarded...
New
Other Trending Topics
Edit: 2026 May 15 - This post is archived.
Mob is alive!!
Main docs: mob v0.7.11 — Documentation
A bit of explanation for the slightly c...
New
Hobbes is a low-level distributed database for the Elixir programming language.
Hobbes provides a simple, safe, and scalable storage lay...
New
A little off-topic, but I feel like people here have a good head on their shoulders.
I used to be quite good at making software. Was luc...
New
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New
Just published claude-code-elixir, a plugin marketplace for Claude Code with Elixir support. These are the plugins I’ve been using for my...
New
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #library
- #deployment
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #podcasts
- #javascript
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ai
- #ecto-query
- #elixirconf-us
- #blog-post
- #elixir-ls
- #phoenix_html
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #elixirconf-eu
- #api
- #forms
- #security
- #metaprogramming











Showing Posts 1 to 3- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
voltone
You can’t use PKCS12 files directly, but that doesn’t mean you have to store the private key in plaintext. You can extract the certificate and key to PEM format using OpenSSL, and set a passphrase for the key. You then pass the ‘:certfile’ and ‘:keyfile’ params, along with the ‘:password’ option.
Or do you mean an external keystore using a PKCS11 interface?
alanj853
Thanks for your help @voltone , I think we will end up having to do just that.
We initially wanted the PKCS12 format, but as long as it is encrypted even in PEM format. I think I we will be okay.
ghannam80
Hello,
I am trying to build a product consuming MC certificates and keys.
I generated the private key using below command:
It generated a file starting like the below:
I am unable using crypto library or public_key to get the private key I need to sign the header , any idea about the support of pkcs12 in elixir or erlang ?
by the way , below link contains the same what I am trying to achieve but using javascript written by MC team :
https://www.npmjs.com/package/mastercard-oauth1-signer?activeTab=readme
thanks in advance