On Fri, Jan 31, 2014, jyri wrote:

> 
> I'm experimenting with some code to generate an RSA signature using
> RSA_NO_PADDING. Instead, I use RSA_padding_add_PKCS1_type_1() to 
> manually add padding to the hash prior to calling EVP_PKEY_sign().
> 
> Attempting to then verify the generated signature conventionally
> (setting padding to RSA_PKCS1_PADDING and letting EVP_PKEY_verify()
> handle it) fails to verify the signature.
> 
> Any thoughts why this doesn't match? Attached is minimal sample test
> case to illustrate the scenario. All error checking is stripped out
> for brevity, but in the real code all return codes are being checked
> and there are no errors, the signature just doesn't verify.
> 

A PKCS#1 signature doesn't just consist of the padded raw digest value it is
contained in a DigestInfo structure which is then padded.

You can create a DigestInfo structure using the ASN1 code and X509_SIG or just
prepend static data to the result: this is what the FIPS code does to avoid
the need to include a full ASN1 encoder in the module.

See the code in fips/rsa/fips_rsa_sign.c in any FIPS version of the master
branch of OpenSSL for details.

Steve.
--
Dr Stephen N. Henson. OpenSSL project core developer.
Commercial tech support now available see: http://www.openssl.org
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [email protected]
Automated List Manager                           [email protected]

Reply via email to