PureBasic
PureBasic
DSA Signature Create and Verify
See more DSA Examples
Shows how to create a DSA (DSS) signature for the contents of a file. The first step is to create an SHA-1 hash of the file contents. The hash is signed using the Digital Signature Algorithm and the signature bytes are retrieved as a hex-encoded string.The 2nd part of the example loads the signature and verifies it against the hash.
Chilkat PureBasic Downloads
IncludeFile "CkCrypt2.pb"
IncludeFile "CkDsa.pb"
Procedure ChilkatExample()
success.i = 0
; This example requires the Chilkat API to have been previously unlocked.
; See Global Unlock Sample for sample code.
crypt.i = CkCrypt2::ckCreate()
If crypt.i = 0
Debug "Failed to create object."
ProcedureReturn
EndIf
CkCrypt2::setCkEncodingMode(crypt, "hex")
CkCrypt2::setCkHashAlgorithm(crypt, "sha-1")
; Return the SHA-1 hash of a file. The file may be any size.
; The Chilkat Crypt component will stream the file when
; computing the hash, keeping the memory usage constant
; and reasonable.
; The 20-byte SHA-1 hash is returned as a hex-encoded string.
hashStr.s = CkCrypt2::ckHashFileENC(crypt,"hamlet.xml")
dsa.i = CkDsa::ckCreate()
If dsa.i = 0
Debug "Failed to create object."
ProcedureReturn
EndIf
; Load a DSA private key from a PEM file. Chilkat DSA
; provides the ability to load and save DSA public and private
; keys from encrypted or non-encrypted PEM or DER.
; The LoadText method is for convenience only. You may
; use any means to load the contents of a PEM file into
; a string.
pemPrivateKey.s
pemPrivateKey = CkDsa::ckLoadText(dsa,"dsa_priv.pem")
success = CkDsa::ckFromPem(dsa,pemPrivateKey)
If success <> 1
Debug CkDsa::ckLastErrorText(dsa)
CkCrypt2::ckDispose(crypt)
CkDsa::ckDispose(dsa)
ProcedureReturn
EndIf
; You may optionally verify the key to ensure that it is a valid
; DSA key.
success = CkDsa::ckVerifyKey(dsa)
If success <> 1
Debug CkDsa::ckLastErrorText(dsa)
CkCrypt2::ckDispose(crypt)
CkDsa::ckDispose(dsa)
ProcedureReturn
EndIf
; Load the hash to be signed into the DSA object:
success = CkDsa::ckSetEncodedHash(dsa,"hex",hashStr)
If success <> 1
Debug CkDsa::ckLastErrorText(dsa)
CkCrypt2::ckDispose(crypt)
CkDsa::ckDispose(dsa)
ProcedureReturn
EndIf
; Now that the DSA object contains both the private key and hash,
; it is ready to create the signature:
success = CkDsa::ckSignHash(dsa)
If success <> 1
Debug CkDsa::ckLastErrorText(dsa)
CkCrypt2::ckDispose(crypt)
CkDsa::ckDispose(dsa)
ProcedureReturn
EndIf
; If SignHash is successful, the DSA object contains the
; signature. It may be accessed as a hex or base64 encoded
; string. (It is also possible to access directly in byte array form via
; the "Signature" property.)
hexSig.s = CkDsa::ckGetEncodedSignature(dsa,"hex")
Debug "Signature:"
Debug hexSig
; -----------------------------------------------------------
; Step 2: Verify the DSA Signature
; -----------------------------------------------------------
dsa2.i = CkDsa::ckCreate()
If dsa2.i = 0
Debug "Failed to create object."
ProcedureReturn
EndIf
; Load the DSA public key to be used for verification:
pemPublicKey.s
pemPublicKey = CkDsa::ckLoadText(dsa2,"dsa_pub.pem")
success = CkDsa::ckFromPublicPem(dsa2,pemPublicKey)
If success <> 1
Debug CkDsa::ckLastErrorText(dsa2)
CkCrypt2::ckDispose(crypt)
CkDsa::ckDispose(dsa)
CkDsa::ckDispose(dsa2)
ProcedureReturn
EndIf
; Load the hash to be verified against the signature.
success = CkDsa::ckSetEncodedHash(dsa2,"hex",hashStr)
If success <> 1
Debug CkDsa::ckLastErrorText(dsa2)
CkCrypt2::ckDispose(crypt)
CkDsa::ckDispose(dsa)
CkDsa::ckDispose(dsa2)
ProcedureReturn
EndIf
; Load the signature:
success = CkDsa::ckSetEncodedSignature(dsa2,"hex",hexSig)
If success <> 1
Debug CkDsa::ckLastErrorText(dsa2)
CkCrypt2::ckDispose(crypt)
CkDsa::ckDispose(dsa)
CkDsa::ckDispose(dsa2)
ProcedureReturn
EndIf
; Verify:
success = CkDsa::ckVerify(dsa2)
If success <> 1
Debug CkDsa::ckLastErrorText(dsa2)
Else
Debug "DSA Signature Verified!"
EndIf
CkCrypt2::ckDispose(crypt)
CkDsa::ckDispose(dsa)
CkDsa::ckDispose(dsa2)
ProcedureReturn
EndProcedure