Sample code for 30+ languages & platforms
Xbase++ Requires Chilkat v11.0.0+

Signing HTTP Messages

See more RSA Examples

Demonstrates how to sign HTTP messages per draft-cavage-http-signatures-10

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL nBCrlf
LOCAL oSbPublicKeyPem
LOCAL oPubKey
LOCAL oSbPrivateKeyPem
LOCAL oPrivKey
LOCAL oDtNow
LOCAL cDateStr
LOCAL oRsa
LOCAL oSbStringToSign
LOCAL cB64Signature

nSuccess := 0

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

nBCrlf := 1
oSbPublicKeyPem := CreateObject("Chilkat.StringBuilder")
oSbPublicKeyPem:AppendLine("-----BEGIN PUBLIC KEY-----", nBCrlf)
oSbPublicKeyPem:AppendLine("MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCFENGw33yGihy92pDjZQhl0C3", nBCrlf)
oSbPublicKeyPem:AppendLine("6rPJj+CvfSC8+q28hxA161QFNUd13wuCTUcq0Qd2qsBe/2hFyc2DCJJg0h1L78+6", nBCrlf)
oSbPublicKeyPem:AppendLine("Z4UMR7EOcpfdUE9Hf3m/hs+FUR45uBJeDK1HSFHD8bHKD6kv8FPGfJTotc+2xjJw", nBCrlf)
oSbPublicKeyPem:AppendLine("oYi+1hqp1fIekaxsyQIDAQAB", nBCrlf)
oSbPublicKeyPem:AppendLine("-----END PUBLIC KEY-----", nBCrlf)

oPubKey := CreateObject("Chilkat.PublicKey")
oPubKey:LoadFromString(oSbPublicKeyPem:GetAsString())

oSbPrivateKeyPem := CreateObject("Chilkat.StringBuilder")
oSbPrivateKeyPem:AppendLine("-----BEGIN RSA PRIVATE KEY-----", nBCrlf)
oSbPrivateKeyPem:AppendLine("MIICXgIBAAKBgQDCFENGw33yGihy92pDjZQhl0C36rPJj+CvfSC8+q28hxA161QF", nBCrlf)
oSbPrivateKeyPem:AppendLine("NUd13wuCTUcq0Qd2qsBe/2hFyc2DCJJg0h1L78+6Z4UMR7EOcpfdUE9Hf3m/hs+F", nBCrlf)
oSbPrivateKeyPem:AppendLine("UR45uBJeDK1HSFHD8bHKD6kv8FPGfJTotc+2xjJwoYi+1hqp1fIekaxsyQIDAQAB", nBCrlf)
oSbPrivateKeyPem:AppendLine("AoGBAJR8ZkCUvx5kzv+utdl7T5MnordT1TvoXXJGXK7ZZ+UuvMNUCdN2QPc4sBiA", nBCrlf)
oSbPrivateKeyPem:AppendLine("QWvLw1cSKt5DsKZ8UETpYPy8pPYnnDEz2dDYiaew9+xEpubyeW2oH4Zx71wqBtOK", nBCrlf)
oSbPrivateKeyPem:AppendLine("kqwrXa/pzdpiucRRjk6vE6YY7EBBs/g7uanVpGibOVAEsqH1AkEA7DkjVH28WDUg", nBCrlf)
oSbPrivateKeyPem:AppendLine("f1nqvfn2Kj6CT7nIcE3jGJsZZ7zlZmBmHFDONMLUrXR/Zm3pR5m0tCmBqa5RK95u", nBCrlf)
oSbPrivateKeyPem:AppendLine("412jt1dPIwJBANJT3v8pnkth48bQo/fKel6uEYyboRtA5/uHuHkZ6FQF7OUkGogc", nBCrlf)
oSbPrivateKeyPem:AppendLine("mSJluOdc5t6hI1VsLn0QZEjQZMEOWr+wKSMCQQCC4kXJEsHAve77oP6HtG/IiEn7", nBCrlf)
oSbPrivateKeyPem:AppendLine("kpyUXRNvFsDE0czpJJBvL/aRFUJxuRK91jhjC68sA7NsKMGg5OXb5I5Jj36xAkEA", nBCrlf)
oSbPrivateKeyPem:AppendLine("gIT7aFOYBFwGgQAQkWNKLvySgKbAZRTeLBacpHMuQdl1DfdntvAyqpAZ0lY0RKmW", nBCrlf)
oSbPrivateKeyPem:AppendLine("G6aFKaqQfOXKCyWoUiVknQJAXrlgySFci/2ueKlIE1QqIiLSZ8V8OlpFLRnb1pzI", nBCrlf)
oSbPrivateKeyPem:AppendLine("7U1yQXnTAEFYM560yJlzUpOb1V4cScGd365tiSMvxLOvTA==", nBCrlf)
oSbPrivateKeyPem:AppendLine("-----END RSA PRIVATE KEY-----", nBCrlf)

oPrivKey := CreateObject("Chilkat.PrivateKey")
oPrivKey:LoadPem(oSbPrivateKeyPem:GetAsString())

//     All examples use this request:
//  
//     POST /foo?param=value&pet=dog HTTP/1.1
//     Host: example.com
//     Date: Sun, 05 Jan 2014 21:31:40 GMT
//     Content-Type: application/json
//     Digest: SHA-256=X48E9qOokqqrvdts8nOJRJN3OWDUoyWxBf7kbu9DBPE=
//     Content-Length: 18
//  
//     {"hello": "world"}

//  C.1.  Default Test
//  
//     If a list of headers is not included, the date is the only header
//     that is signed by default.  The string to sign would be:
//  
//     date: Sun, 05 Jan 2014 21:31:40 GMT
//  
//     The Authorization header would be:
//  
//     Authorization: Signature keyId="Test",algorithm="rsa-sha256",
//     signature="SjWJWbWN7i0wzBvtPl8rbASWz5xQW6mcJmn+ibttBqtifLN7Sazz
//     6m79cNfwwb8DMJ5cou1s7uEGKKCs+FLEEaDV5lp7q25WqS+lavg7T8hc0GppauB
//     6hbgEKTwblDHYGEtbGmtdHgVCk9SuS13F0hZ8FD0k/5OxEPXe5WozsbM="
//  
//     The Signature header would be:
//  
//     Signature: keyId="Test",algorithm="rsa-sha256",
//     signature="SjWJWbWN7i0wzBvtPl8rbASWz5xQW6mcJmn+ibttBqtifLN7Sazz
//     6m79cNfwwb8DMJ5cou1s7uEGKKCs+FLEEaDV5lp7q25WqS+lavg7T8hc0GppauB
//     6hbgEKTwblDHYGEtbGmtdHgVCk9SuS13F0hZ8FD0k/5OxEPXe5WozsbM="
//  

oDtNow := CreateObject("Chilkat.CkDateTime")
nSuccess := oDtNow:SetFromCurrentSystemTime()
cDateStr := oDtNow:GetAsRfc822(0)

//  To duplicate the above result, we'll hard-code the date string.
cDateStr := "Sun, 05 Jan 2014 21:31:40 GMT"

oRsa := CreateObject("Chilkat.Rsa")
nSuccess := oRsa:UsePrivateKey(oPrivKey)
IF (nSuccess == 0)
    ? oRsa:LastErrorText
    oSbPublicKeyPem:destroy()
    oPubKey:destroy()
    oSbPrivateKeyPem:destroy()
    oPrivKey:destroy()
    oDtNow:destroy()
    oRsa:destroy()
    RETURN
ENDIF

oSbStringToSign := CreateObject("Chilkat.StringBuilder")
oSbStringToSign:Append("date: ")
oSbStringToSign:Append(cDateStr)

oRsa:EncodingMode := "base64"
cB64Signature := oRsa:SignStringENC(oSbStringToSign:GetAsString(), "SHA256")
? cB64Signature
? "---------------------------"

//  The result should be:
//  SjWJWbWN7i0wzBvtPl8rbASW ... FD0k/5OxEPXe5WozsbM=

//  ----------------------------------------------------------------------------------------------------

//  C.2.  Basic Test
//  
//     The minimum recommended data to sign is the (request-target), host,
//     and date.  In this case, the string to sign would be:
//  
//     (request-target): post /foo?param=value&pet=dog
//     host: example.com
//     date: Sun, 05 Jan 2014 21:31:40 GMT
//  
//     The Authorization header would be:
//  
//     Authorization: Signature keyId="Test",algorithm="rsa-sha256",
//     headers="(request-target) host date", signature="qdx+H7PHHDZgy4
//     y/Ahn9Tny9V3GP6YgBPyUXMmoxWtLbHpUnXS2mg2+SbrQDMCJypxBLSPQR2aAjn
//     7ndmw2iicw3HMbe8VfEdKFYRqzic+efkb3nndiv/x1xSHDJWeSWkx3ButlYSuBs
//     kLu6kd9Fswtemr3lgdDEmn04swr2Os0="

oSbStringToSign:Clear()
oSbStringToSign:Append("(request-target): ")
oSbStringToSign:AppendLine("post /foo?param=value&pet=dog", 0)
oSbStringToSign:Append("host: ")
oSbStringToSign:AppendLine("example.com", 0)
oSbStringToSign:Append("date: ")
oSbStringToSign:Append(cDateStr)

? "StringToSign:"
? oSbStringToSign:GetAsString()
cB64Signature := oRsa:SignStringENC(oSbStringToSign:GetAsString(), "SHA256")
? cB64Signature
? "---------------------------"

//  The result should be:
//  qdx+H7PHHDZgy4y/Ahn ... mn04swr2Os0=

oSbPublicKeyPem:destroy()
oPubKey:destroy()
oSbPrivateKeyPem:destroy()
oPrivKey:destroy()
oDtNow:destroy()
oRsa:destroy()
oSbStringToSign:destroy()