On Wed, Dec 15, 2004, Andrus wrote:

> Stephen,
> 
> thank you.
> 
> The command
> 
> openssl rsautl -verify -in signature.bin -inkey public.der -pubin -keyform
> DER -out signout.bin
> 
> Causes error:
> 
> RSA operation error
> 4294560507:error:0407006A:rsa routines:RSA_padding_check_PKCS1_type_1:block
> type
>  is not 01:crypto/rsa/rsa_pk1.c:100:
> 4294560507:error:04067072:rsa routines:RSA_EAY_PUBLIC_DECRYPT:padding check
> fail
> ed:crypto/rsa/rsa_eay.c:580:
> 
> If I replace signature.bin  with sign.bin file, all is OK
> 
> Why signature.bin causes error ?
> 
> 

Various padding bytes are added before encryption and removed (and checked)
after decryption using RSA: the full details are in the PKCs#1 standard. 

The error means that the padding wasn't of the correct form. Other than that
its hard to say what the problem is. Turning off padding (using -raw) doesn't
help: the decrypted data looks like garbage.

Where does 'signature.bin' come from?

BTW to answer your other question the format of the public key is defined in
the various standards mentioned. You can use various OpenSSL utilities to pase
the structure. For example:

 openssl rsa -inform DER -pubin -in public.der -text -noout

gives:


Modulus (1024 bit):
    00:ce:fa:21:c8:a1:02:3b:7b:81:50:2e:b9:aa:4a:
    8e:b3:43:82:c7:7f:7b:56:76:90:45:c2:0d:28:1e:
    55:22:9d:78:4d:0a:ff:0b:c8:7b:ec:fc:59:a4:65:
    f5:f4:f1:b5:96:5f:76:d0:ad:60:a3:e4:2e:cc:7d:
    40:4c:5a:2f:b5:d1:58:49:3c:f1:0e:71:eb:61:6e:
    da:ad:80:2b:7d:e1:1c:86:83:5e:ba:00:ea:19:0c:
    b0:42:4c:a8:78:80:f0:3c:f5:bd:fd:27:78:8b:30:
    94:d8:93:39:5d:33:da:1f:68:f1:bb:d3:35:cf:a6:
    dd:08:ca:b8:db:b7:a6:3c:df
Exponent: 3 (0x3)

To see the ASN1 structure you can use:

openssl asn1parse -inform DER -in public.der

which produces:

    0:d=0  hl=3 l= 157 cons: SEQUENCE          
    3:d=1  hl=2 l=  13 cons: SEQUENCE          
    5:d=2  hl=2 l=   9 prim: OBJECT            :rsaEncryption
   16:d=2  hl=2 l=   0 prim: NULL              
   18:d=1  hl=3 l= 139 prim: BIT STRING        

The key components are in that BIT STRING which you can see with:

openssl asn1parse -inform DER -in public.der -strparse 18


    0:d=0  hl=3 l= 135 cons: SEQUENCE          
    3:d=1  hl=3 l= 129 prim: INTEGER           
:CEFA21C8A1023B7B81502EB9AA4A8EB34382C77F7B56769045C20D281E55229D784D0AFF0BC87BECFC59A465F5F4F1B5965F76D0AD60A3E42ECC7D404C5A2FB5D158493CF10E71EB616EDAAD802B7DE11C86835EBA00EA190CB0424CA87880F03CF5BDFD27788B3094D893395D33DA1F68F1BBD335CFA6DD08CAB8DBB7A63CDF
  135:d=1  hl=2 l=   1 prim: INTEGER           :03

Steve.
--
Dr Stephen N. Henson. Email, S/MIME and PGP keys: see homepage
OpenSSL project core developer and freelance consultant.
Funding needed! Details on homepage.
Homepage: http://www.drh-consultancy.demon.co.uk
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to