Sample code for 30+ languages & platforms
Rust

Create ECSDA Signature using Raw r and s Format (not ASN.1)

See more ECC Examples

Demonstrates how to create an ECDSA signature using the raw r/s format.

ECDSA signatures have two equal sized parts, r and s. There are two common formats for encoding the signature:

(a) Concatenating the raw byte array of r and s
(b) Encoding both into a structured ASN.1 / DER sequence.

This example demonstrates how to create a signature that is a byte array of r and s concatenated.

Note: This example requires Chilkat v9.5.0.97 or greater.

Chilkat Rust Downloads

Rust

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

// To create an ECDSA signature, the data first needs to be hashed.  Then the hash
// is signed.

let sb = chilkat::StringBuilder::new();
let _ = sb.append("The quick brown fox jumps over the lazy dog");
let hash = sb.get_hash("sha256", "base64", "utf-8").unwrap_or_default();

// Load the ECDSA key to be used for signing.
let priv_key = chilkat::PrivateKey::new();
if priv_key.load_pem_file("qa_data/ecc/secp256r1-key-pkcs8.pem").is_err() {
    println!("{}", priv_key.last_error_text());
    return;
}

let prng = chilkat::Prng::new();
let ecdsa = chilkat::Ecc::new();

// Produce a signature that is not ASN.1, but is instead the concatenation
// of the raw r and s signature parts.
// This feature was added in Chilkat v9.5.0.97
ecdsa.set_asn_format(false);

let Ok(ecdsa_sig_base64) = ecdsa.sign_hash_enc(&hash, "base64", &priv_key, &prng) else {
    println!("{}", ecdsa.last_error_text());
    return;
};

println!("ECDSA signature = {}", ecdsa_sig_base64);

// -----------------------------------------------------------
// Now let's verify the signature using the public key.

let pub_key = chilkat::PublicKey::new();
if pub_key.load_from_file("qa_data/ecc/secp256r1-pubkey.pem").is_err() {
    println!("{}", pub_key.last_error_text());
    return;
}

// Note: When verifying, Chilkat will auto-detect the format for both kinds of ECDSA signatures (ASN.1 or binary r+s)
let result = ecdsa.verify_hash_enc(&hash, &ecdsa_sig_base64, "base64", &pub_key);
if result == 1 {
    println!("Signature is valid.");
    return;
}

if result == 0 {
    println!("Signature is invalid.");
    return;
}

if result < 0 {
    println!("{}", ecdsa.last_error_text());
    println!("The VerifyHashENC method call failed.");
    return;
}