Hi,

I'm in the process of developing a dig. sig. implementation for a project.
The signature data needs to be appended to a URL query string in the form of
a name/value pair, and then unbundled on the other side and verified.  The
signing side is Java and the verify side is C++ using OpenSSL.

So far, I've been able to write a Java signature out to a file, read it into
a C++ program and verify it using OpenSSL.

My questions are:

1.  Do I need to base64 encode the signature data?  I'm using the default
SUN crypto provider in JDK 1.2 to create a DSS signature, but I don't know
what format the data is in.  The returned signature is just a byte[] object,
and I don't know what the encoding is.

2.  Is DER-encoding base64 by default?  The OpenSSL EVP signature functions
are able to verify the signature, and from the man pages the EVP functions
expecte DER-encoded signature data.  From this I ASSuME the Java byte[] is
DER-encoded as well.  

3.  If I need to do base64 encoding on my own, can I use the
EVP_EncodeXXXX() methods to do general base64 encoding/decoding?

Any help is greatly appreciated...this seems to be the last missing piece to
me getting this stuff done (and as usual, it needs to be done yesterday).

Thanks,

Mike




______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to