使用Crypto庫簽名和驗證簽名請參考Crypto庫實現PKCS7簽名與簽名驗證,可使用OpenSSL庫驗證Crypto簽名,OpenSSL驗證簽名可以使用簡單的代碼描述以下:編碼
- int Openssl_Verify(unsigned char* signature_msg,unsigned int length)
- {
- unsigned char message[1024];
- int message_length = 0;
-
- const unsigned char* p_signature_msg = signature_msg;
-
-
- PKCS7* p7 = d2i_PKCS7(NULL,&p_signature_msg,length);
-
- if (p7 == NULL)
- {
- printf("error.\n");
-
- return 0;
- }
-
-
- BIO *p7bio= PKCS7_dataDecode(p7,NULL,NULL,NULL);
-
-
- dwMessageLen = BIO_read(p7bio,message,1024);
-
- STACK_OF(PKCS7_SIGNER_INFO) *sk = PKCS7_get_signer_info(p7);
-
-
- int signCount = sk_PKCS7_SIGNER_INFO_num(sk );
-
- for (int i = 0;i < signCount;i++)
- {
-
- PKCS7_SIGNER_INFO *signInfo = sk_PKCS7_SIGNER_INFO_value(sk,i);
-
-
- X509 *cert= PKCS7_cert_from_signer_info(p7,signInfo);
-
-
- if (PKCS7_signatureVerify(p7bio,p7,signInfo,cert) != 1)
- {
- printf("signature verify error.\n");
-
- return 0;
- }
- }
-
- return 1;
- }