help-gnutls
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: RSA sign/verify and hash generation functions


From: Murray S. Kucherawy
Subject: RE: RSA sign/verify and hash generation functions
Date: Thu, 9 Dec 2010 10:13:47 -0800

> -----Original Message-----
> From: Nikos Mavrogiannopoulos [mailto:address@hidden On Behalf Of Nikos 
> Mavrogiannopoulos
> Sent: Thursday, December 09, 2010 12:23 AM
> To: Murray S. Kucherawy
> Cc: address@hidden
> Subject: Re: RSA sign/verify and hash generation functions
> 
> > I did.  By the looks of things, the *_sign_hash() functions look like
> > they sign a hash that's already been computed, which is the case for
> > me, so that's what I used.
> 
> The current sign_hash function is not what you want. They are tricky to
> use to generate correct signatures (for DSA they work ok, but for RSA
> require one more step to generate a PKCS #1 compliant signature - i.e.
> BER encode the hash as DigestInfo). I'll add a safer to use API for
> 2.12.x and deprecate those functions.

OK.  If you would like me to try those out once they're available, just point 
me at the tarball.

reply via email to

[Prev in Thread] Current Thread [Next in Thread]