Sample code for 30+ languages & platforms
Tcl

Create ECSDA Signature using Raw r and s Format (not ASN.1)

See more ECC Examples

Demonstrates how to create an ECDSA signature using the raw r/s format.

ECDSA signatures have two equal sized parts, r and s. There are two common formats for encoding the signature:

(a) Concatenating the raw byte array of r and s
(b) Encoding both into a structured ASN.1 / DER sequence.

This example demonstrates how to create a signature that is a byte array of r and s concatenated.

Note: This example requires Chilkat v9.5.0.97 or greater.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.

# To create an ECDSA signature, the data first needs to be hashed.  Then the hash
# is signed.

set sb [new_CkStringBuilder]

CkStringBuilder_Append $sb "The quick brown fox jumps over the lazy dog"
set hash [CkStringBuilder_getHash $sb "sha256" "base64" "utf-8"]

# Load the ECDSA key to be used for signing.
set privKey [new_CkPrivateKey]

set success [CkPrivateKey_LoadPemFile $privKey "qa_data/ecc/secp256r1-key-pkcs8.pem"]
if {$success != 1} then {
    puts [CkPrivateKey_lastErrorText $privKey]
    delete_CkStringBuilder $sb
    delete_CkPrivateKey $privKey
    exit
}

set prng [new_CkPrng]

set ecdsa [new_CkEcc]

# Produce a signature that is not ASN.1, but is instead the concatenation
# of the raw r and s signature parts.
# This feature was added in Chilkat v9.5.0.97
CkEcc_put_AsnFormat $ecdsa 0

set ecdsaSigBase64 [CkEcc_signHashENC $ecdsa $hash "base64" $privKey $prng]
if {[CkEcc_get_LastMethodSuccess $ecdsa] != 1} then {
    puts [CkEcc_lastErrorText $ecdsa]
    delete_CkStringBuilder $sb
    delete_CkPrivateKey $privKey
    delete_CkPrng $prng
    delete_CkEcc $ecdsa
    exit
}

puts "ECDSA signature = $ecdsaSigBase64"

# -----------------------------------------------------------
# Now let's verify the signature using the public key.

set pubKey [new_CkPublicKey]

set success [CkPublicKey_LoadFromFile $pubKey "qa_data/ecc/secp256r1-pubkey.pem"]
if {$success != 1} then {
    puts [CkPublicKey_lastErrorText $pubKey]
    delete_CkStringBuilder $sb
    delete_CkPrivateKey $privKey
    delete_CkPrng $prng
    delete_CkEcc $ecdsa
    delete_CkPublicKey $pubKey
    exit
}

# Note: When verifying, Chilkat will auto-detect the format for both kinds of ECDSA signatures (ASN.1 or binary r+s)
set result [CkEcc_VerifyHashENC $ecdsa $hash $ecdsaSigBase64 "base64" $pubKey]
if {$result == 1} then {
    puts "Signature is valid."
    delete_CkStringBuilder $sb
    delete_CkPrivateKey $privKey
    delete_CkPrng $prng
    delete_CkEcc $ecdsa
    delete_CkPublicKey $pubKey
    exit
}

if {$result == 0} then {
    puts "Signature is invalid."
    delete_CkStringBuilder $sb
    delete_CkPrivateKey $privKey
    delete_CkPrng $prng
    delete_CkEcc $ecdsa
    delete_CkPublicKey $pubKey
    exit
}

if {$result < 0} then {
    puts [CkEcc_lastErrorText $ecdsa]
    puts "The VerifyHashENC method call failed."
    delete_CkStringBuilder $sb
    delete_CkPrivateKey $privKey
    delete_CkPrng $prng
    delete_CkEcc $ecdsa
    delete_CkPublicKey $pubKey
    exit
}


delete_CkStringBuilder $sb
delete_CkPrivateKey $privKey
delete_CkPrng $prng
delete_CkEcc $ecdsa
delete_CkPublicKey $pubKey