Sample code for 30+ languages & platforms
Zig

ECDSA Sign and Verify Data using Different Hash Algorithms

See more ECC Examples

Demonstrates how to create ECDSA signatures on data using different hash algorithms.

Note: This example requires Chilkat v9.5.0.85 or greater because the SignBd and VerifyBd methods were added in v9.5.0.85.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example assumes the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // First load an ECDSA private key to be used for signing.
    const priv_key = try chilkat.PrivateKey.init();
    defer priv_key.deinit();
    priv_key.loadEncryptedPemFile("qa_data/ecc/secp256r1-key-pkcs8-secret.pem", "secret") catch {
        std.debug.print("{s}\n", .{try priv_key.getLastErrorText(alloc)});
        return;
    };

    // Load some data to be signed.
    const bd = try chilkat.BinData.init();
    defer bd.deinit();
    bd.loadFile("qa_data/hamlet.xml") catch {
        std.debug.print("Failed to load file to be hashed.\n", .{});
        return;
    };

    const ecdsa = try chilkat.Ecc.init();
    defer ecdsa.deinit();
    const prng = try chilkat.Prng.init();
    defer prng.deinit();

    // Sign the sha256 hash of the data.  Return the ECDSA signature in the base64 encoding.
    std.debug.print("ECDSA signing the sha256 hash of the data...\n", .{});
    var sig: [:0]const u8 = try ecdsa.signBd(alloc, bd, "sha256", "base64", priv_key, prng);
    std.debug.print("sig = {s}\n", .{sig});

    // Verify the signature against the original data.
    // (We must use the same hash algorithm that was used when signing.)

    // Load the public key that corresponds to the private key used for signing.
    const pub_key = try chilkat.PublicKey.init();
    defer pub_key.deinit();
    pub_key.loadFromFile("qa_data/ecc/secp256r1-pub.pem") catch {
        std.debug.print("{s}\n", .{try pub_key.getLastErrorText(alloc)});
        return;
    };

    const ecc2 = try chilkat.Ecc.init();
    defer ecc2.deinit();
    var result: i32 = ecc2.verifyBd(bd, "sha256", sig, "base64", pub_key);
    if (result != 1) {
        std.debug.print("{s}\n", .{try ecc2.getLastErrorText(alloc)});
        return;
    }

    std.debug.print("Verified!\n", .{});

    // ----------------------------------------------------------------------------------------
    // Let's do the same thing, but with sha384 hashing...

    std.debug.print("--------------------------------------------\n", .{});
    std.debug.print("ECDSA signing the sha384 hash of the data...\n", .{});

    sig = try ecdsa.signBd(alloc, bd, "sha384", "base64", priv_key, prng);
    std.debug.print("sig = {s}\n", .{sig});

    result = ecc2.verifyBd(bd, "sha384", sig, "base64", pub_key);
    if (result != 1) {
        std.debug.print("{s}\n", .{try ecc2.getLastErrorText(alloc)});
        return;
    }

    std.debug.print("Verified!\n", .{});
}