Sample code for 30+ languages & platforms
Xbase++

DSA Signature Create and Verify

See more DSA Examples

Shows how to create a DSA (DSS) signature for the contents of a file. The first step is to create an SHA-1 hash of the file contents. The hash is signed using the Digital Signature Algorithm and the signature bytes are retrieved as a hex-encoded string.

The 2nd part of the example loads the signature and verifies it against the hash.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oCrypt
LOCAL cHashStr
LOCAL oDsa
LOCAL cPemPrivateKey
LOCAL cHexSig
LOCAL oDsa2
LOCAL cPemPublicKey

nSuccess := 0

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

oCrypt := CreateObject("Chilkat.Crypt2")

oCrypt:EncodingMode := "hex"
oCrypt:HashAlgorithm := "sha-1"

//  Return the SHA-1 hash of a file.  The file may be any size.
//  The Chilkat Crypt component will stream the file when 
//  computing the hash, keeping the memory usage constant
//  and reasonable.
//  The 20-byte SHA-1 hash is returned as a hex-encoded string.
cHashStr := oCrypt:HashFileENC("hamlet.xml")

oDsa := CreateObject("Chilkat.Dsa")

//  Load a DSA private key from a PEM file.  Chilkat DSA
//  provides the ability to load and save DSA public and private
//  keys from encrypted or non-encrypted PEM or DER.
//  The LoadText method is for convenience only.  You may
//  use any means to load the contents of a PEM file into
//  a string.

cPemPrivateKey := oDsa:LoadText("dsa_priv.pem")
nSuccess := oDsa:FromPem(cPemPrivateKey)
IF (nSuccess != 1)
    ? oDsa:LastErrorText
    oCrypt:destroy()
    oDsa:destroy()
    RETURN
ENDIF

//  You may optionally verify the key to ensure that it is a valid
//  DSA key.
nSuccess := oDsa:VerifyKey()
IF (nSuccess != 1)
    ? oDsa:LastErrorText
    oCrypt:destroy()
    oDsa:destroy()
    RETURN
ENDIF

//  Load the hash to be signed into the DSA object:
nSuccess := oDsa:SetEncodedHash("hex", cHashStr)
IF (nSuccess != 1)
    ? oDsa:LastErrorText
    oCrypt:destroy()
    oDsa:destroy()
    RETURN
ENDIF

//  Now that the DSA object contains both the private key and hash,
//  it is ready to create the signature:
nSuccess := oDsa:SignHash()
IF (nSuccess != 1)
    ? oDsa:LastErrorText
    oCrypt:destroy()
    oDsa:destroy()
    RETURN
ENDIF

//  If SignHash is successful, the DSA object contains the
//  signature.  It may be accessed as a hex or base64 encoded
//  string.  (It is also possible to access directly in byte array form via
//  the "Signature" property.)
cHexSig := oDsa:GetEncodedSignature("hex")
? "Signature:"
? cHexSig

//  -----------------------------------------------------------
//  Step 2: Verify the DSA Signature
//  -----------------------------------------------------------

oDsa2 := CreateObject("Chilkat.Dsa")

//  Load the DSA public key to be used for verification:

cPemPublicKey := oDsa2:LoadText("dsa_pub.pem")
nSuccess := oDsa2:FromPublicPem(cPemPublicKey)
IF (nSuccess != 1)
    ? oDsa2:LastErrorText
    oCrypt:destroy()
    oDsa:destroy()
    oDsa2:destroy()
    RETURN
ENDIF

//  Load the hash to be verified against the signature.
nSuccess := oDsa2:SetEncodedHash("hex", cHashStr)
IF (nSuccess != 1)
    ? oDsa2:LastErrorText
    oCrypt:destroy()
    oDsa:destroy()
    oDsa2:destroy()
    RETURN
ENDIF

//  Load the signature:
nSuccess := oDsa2:SetEncodedSignature("hex", cHexSig)
IF (nSuccess != 1)
    ? oDsa2:LastErrorText
    oCrypt:destroy()
    oDsa:destroy()
    oDsa2:destroy()
    RETURN
ENDIF

//  Verify:
nSuccess := oDsa2:Verify()
IF (nSuccess != 1)
    ? oDsa2:LastErrorText
ELSE
    ? "DSA Signature Verified!"
ENDIF

oCrypt:destroy()
oDsa:destroy()
oDsa2:destroy()