On Wed, Jul 12, 2000 at 09:46:55AM -0400, Cico, Michael wrote:
>
> Hi,
>
> I'm in the process of developing a dig. sig. implementation for a project.
> The signature data needs to be appended to a URL query string in the form of
> a name/value pair, and then unbundled on the other side and verified. The
> signing side is Java and the verify side is C++ using OpenSSL.
>
> So far, I've been able to write a Java signature out to a file, read it into
> a C++ program and verify it using OpenSSL.
>
> My questions are:
>
> 1. Do I need to base64 encode the signature data?
If you're sending in an URL over HTTP (as opposed to
in some other HTTP header or in the body) then you do.
> I'm using the default
> SUN crypto provider in JDK 1.2 to create a DSS signature, but I don't know
> what format the data is in. The returned signature is just a byte[] object,
> and I don't know what the encoding is.
If it starts with 0x30,0x8{1,2,3} it's probably DER.
> 2. Is DER-encoding base64 by default?
Nope.
--
Eric Murray www.lne.com/~ericm ericm at the site lne.com PGP keyid:E03F65E5
Security consulting: security models, reviews, protocols, crypto.
______________________________________________________________________
OpenSSL Project http://www.openssl.org
User Support Mailing List [EMAIL PROTECTED]
Automated List Manager [EMAIL PROTECTED]