Hi,
I'm in the process of developing a dig. sig. implementation for a project.
The signature data needs to be appended to a URL query string in the form of
a name/value pair, and then unbundled on the other side and verified. The
signing side is Java and the verify side is C++ using OpenSSL.
So far, I've been able to write a Java signature out to a file, read it into
a C++ program and verify it using OpenSSL.
My questions are:
1. Do I need to base64 encode the signature data? I'm using the default
SUN crypto provider in JDK 1.2 to create a DSS signature, but I don't know
what format the data is in. The returned signature is just a byte[] object,
and I don't know what the encoding is.
2. Is DER-encoding base64 by default? The OpenSSL EVP signature functions
are able to verify the signature, and from the man pages the EVP functions
expecte DER-encoded signature data. From this I ASSuME the Java byte[] is
DER-encoded as well.
3. If I need to do base64 encoding on my own, can I use the
EVP_EncodeXXXX() methods to do general base64 encoding/decoding?
Any help is greatly appreciated...this seems to be the last missing piece to
me getting this stuff done (and as usual, it needs to be done yesterday).
Thanks,
Mike
______________________________________________________________________
OpenSSL Project http://www.openssl.org
User Support Mailing List [EMAIL PROTECTED]
Automated List Manager [EMAIL PROTECTED]