On Fri, Jan 31, 2014, jyri wrote: > > I'm experimenting with some code to generate an RSA signature using > RSA_NO_PADDING. Instead, I use RSA_padding_add_PKCS1_type_1() to > manually add padding to the hash prior to calling EVP_PKEY_sign(). > > Attempting to then verify the generated signature conventionally > (setting padding to RSA_PKCS1_PADDING and letting EVP_PKEY_verify() > handle it) fails to verify the signature. > > Any thoughts why this doesn't match? Attached is minimal sample test > case to illustrate the scenario. All error checking is stripped out > for brevity, but in the real code all return codes are being checked > and there are no errors, the signature just doesn't verify. >
A PKCS#1 signature doesn't just consist of the padded raw digest value it is contained in a DigestInfo structure which is then padded. You can create a DigestInfo structure using the ASN1 code and X509_SIG or just prepend static data to the result: this is what the FIPS code does to avoid the need to include a full ASN1 encoder in the module. See the code in fips/rsa/fips_rsa_sign.c in any FIPS version of the master branch of OpenSSL for details. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [email protected] Automated List Manager [email protected]
