Rust
Rust
Create ECSDA Signature using Raw r and s Format (not ASN.1)
See more ECC Examples
Demonstrates how to create an ECDSA signature using the raw r/s format.ECDSA signatures have two equal sized parts, r and s. There are two common formats for encoding the signature:
(a) Concatenating the raw byte array of r and s
(b) Encoding both into a structured ASN.1 / DER sequence.
This example demonstrates how to create a signature that is a byte array of r and s concatenated.
Note: This example requires Chilkat v9.5.0.97 or greater.
Chilkat Rust Downloads
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
// To create an ECDSA signature, the data first needs to be hashed. Then the hash
// is signed.
let sb = chilkat::StringBuilder::new();
let _ = sb.append("The quick brown fox jumps over the lazy dog");
let hash = sb.get_hash("sha256", "base64", "utf-8").unwrap_or_default();
// Load the ECDSA key to be used for signing.
let priv_key = chilkat::PrivateKey::new();
if priv_key.load_pem_file("qa_data/ecc/secp256r1-key-pkcs8.pem").is_err() {
println!("{}", priv_key.last_error_text());
return;
}
let prng = chilkat::Prng::new();
let ecdsa = chilkat::Ecc::new();
// Produce a signature that is not ASN.1, but is instead the concatenation
// of the raw r and s signature parts.
// This feature was added in Chilkat v9.5.0.97
ecdsa.set_asn_format(false);
let Ok(ecdsa_sig_base64) = ecdsa.sign_hash_enc(&hash, "base64", &priv_key, &prng) else {
println!("{}", ecdsa.last_error_text());
return;
};
println!("ECDSA signature = {}", ecdsa_sig_base64);
// -----------------------------------------------------------
// Now let's verify the signature using the public key.
let pub_key = chilkat::PublicKey::new();
if pub_key.load_from_file("qa_data/ecc/secp256r1-pubkey.pem").is_err() {
println!("{}", pub_key.last_error_text());
return;
}
// Note: When verifying, Chilkat will auto-detect the format for both kinds of ECDSA signatures (ASN.1 or binary r+s)
let result = ecdsa.verify_hash_enc(&hash, &ecdsa_sig_base64, "base64", &pub_key);
if result == 1 {
println!("Signature is valid.");
return;
}
if result == 0 {
println!("Signature is invalid.");
return;
}
if result < 0 {
println!("{}", ecdsa.last_error_text());
println!("The VerifyHashENC method call failed.");
return;
}