Steve, Your advice is very much appreciated. Thanks again for resolving this issue for me so quickly.
Kind regards, Bob D. -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Dr. Stephen Henson Sent: donderdag 28 oktober 2010 14:31 To: [email protected] Subject: Re: rsa_sign versus RSA_private_encrypt On Thu, Oct 28, 2010, Bob Dijck wrote: > Thank you, Steve, for the swift reply. > Can I use i2d_X509_SIG to perform to encapsulation step (supposing I have to > use RSA_private_encrypt)? > Well you can if you want but RSA_sign() does all that for you. There is an easier way: the encapsulation effectively prepends fixed data to the signature. The FIPS libraries use this technique to avoid having to drag in the whole ASN1 library. The prepended data depends on the digest type, you can get the required prefix from the file fips/rsa/fips_rsa_sign.c in OpenSSL 0.9.8. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [email protected] Automated List Manager [email protected] This e-mail and any attachments contain material that is confidential for the sole use of the intended recipient. Any review, reliance or distribution by others or forwarding without express permission is strictly prohibited. If you are not the intended recipient, please contact the sender and delete all copies. ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [email protected] Automated List Manager [email protected]
