Sample code for 30+ languages & platforms
Objective-C

DSA Signature Create and Verify

See more DSA Examples

Shows how to create a DSA (DSS) signature for the contents of a file. The first step is to create an SHA-1 hash of the file contents. The hash is signed using the Digital Signature Algorithm and the signature bytes are retrieved as a hex-encoded string.

The 2nd part of the example loads the signature and verifies it against the hash.

Chilkat Objective-C Downloads

Objective-C
#import <CkoCrypt2.h>
#import <NSString.h>
#import <CkoDsa.h>

BOOL success = NO;

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

CkoCrypt2 *crypt = [[CkoCrypt2 alloc] init];

crypt.EncodingMode = @"hex";
crypt.HashAlgorithm = @"sha-1";

//  Return the SHA-1 hash of a file.  The file may be any size.
//  The Chilkat Crypt component will stream the file when 
//  computing the hash, keeping the memory usage constant
//  and reasonable.
//  The 20-byte SHA-1 hash is returned as a hex-encoded string.
NSString *hashStr = [crypt HashFileENC: @"hamlet.xml"];

CkoDsa *dsa = [[CkoDsa alloc] init];

//  Load a DSA private key from a PEM file.  Chilkat DSA
//  provides the ability to load and save DSA public and private
//  keys from encrypted or non-encrypted PEM or DER.
//  The LoadText method is for convenience only.  You may
//  use any means to load the contents of a PEM file into
//  a string.
NSString *pemPrivateKey = 0;
pemPrivateKey = [dsa LoadText: @"dsa_priv.pem"];
success = [dsa FromPem: pemPrivateKey];
if (success != YES) {
    NSLog(@"%@",dsa.LastErrorText);
    return;
}

//  You may optionally verify the key to ensure that it is a valid
//  DSA key.
success = [dsa VerifyKey];
if (success != YES) {
    NSLog(@"%@",dsa.LastErrorText);
    return;
}

//  Load the hash to be signed into the DSA object:
success = [dsa SetEncodedHash: @"hex" encodedHash: hashStr];
if (success != YES) {
    NSLog(@"%@",dsa.LastErrorText);
    return;
}

//  Now that the DSA object contains both the private key and hash,
//  it is ready to create the signature:
success = [dsa SignHash];
if (success != YES) {
    NSLog(@"%@",dsa.LastErrorText);
    return;
}

//  If SignHash is successful, the DSA object contains the
//  signature.  It may be accessed as a hex or base64 encoded
//  string.  (It is also possible to access directly in byte array form via
//  the "Signature" property.)
NSString *hexSig = [dsa GetEncodedSignature: @"hex"];
NSLog(@"%@",@"Signature:");
NSLog(@"%@",hexSig);

//  -----------------------------------------------------------
//  Step 2: Verify the DSA Signature
//  -----------------------------------------------------------

CkoDsa *dsa2 = [[CkoDsa alloc] init];

//  Load the DSA public key to be used for verification:
NSString *pemPublicKey = 0;
pemPublicKey = [dsa2 LoadText: @"dsa_pub.pem"];
success = [dsa2 FromPublicPem: pemPublicKey];
if (success != YES) {
    NSLog(@"%@",dsa2.LastErrorText);
    return;
}

//  Load the hash to be verified against the signature.
success = [dsa2 SetEncodedHash: @"hex" encodedHash: hashStr];
if (success != YES) {
    NSLog(@"%@",dsa2.LastErrorText);
    return;
}

//  Load the signature:
success = [dsa2 SetEncodedSignature: @"hex" encodedSig: hexSig];
if (success != YES) {
    NSLog(@"%@",dsa2.LastErrorText);
    return;
}

//  Verify:
success = [dsa2 Verify];
if (success != YES) {
    NSLog(@"%@",dsa2.LastErrorText);
}
else {
    NSLog(@"%@",@"DSA Signature Verified!");
}