On Wed, Jul 12, 2000 at 09:46:55AM -0400, Cico, Michael wrote:
> 
> Hi,
> 
> I'm in the process of developing a dig. sig. implementation for a project.
> The signature data needs to be appended to a URL query string in the form of
> a name/value pair, and then unbundled on the other side and verified.  The
> signing side is Java and the verify side is C++ using OpenSSL.
> 
> So far, I've been able to write a Java signature out to a file, read it into
> a C++ program and verify it using OpenSSL.
> 
> My questions are:
> 
> 1.  Do I need to base64 encode the signature data? 

If you're sending in an URL over HTTP (as opposed to
in some other HTTP header or in the body) then you do.

> I'm using the default
> SUN crypto provider in JDK 1.2 to create a DSS signature, but I don't know
> what format the data is in.  The returned signature is just a byte[] object,
> and I don't know what the encoding is.

If it starts with 0x30,0x8{1,2,3} it's probably DER.

> 2.  Is DER-encoding base64 by default?

Nope.


-- 
 Eric Murray www.lne.com/~ericm  ericm at the site lne.com  PGP keyid:E03F65E5
    Security consulting: security models, reviews, protocols, crypto.
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to