RSACryptoServiceProvider.Verify*

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • Marian Dvorsky

    #1

    RSACryptoServiceProvider.Verify*

    There are two methods in RSACryptoServic eProvider to verify signed data:

    VerifyData(byte[] buffer, object halg, byte[] signature)
    VerifyHash(byte[] rgbHash, string str, byte[] rgbSignature)

    What is not clear to me is, why the second method (VerifyHash()) needs OID
    of used
    hash algorithm. Probably, it is used to compare it to the OID saved in a
    signature.
    But, when there is OID to compare to, then why VerifyData needs the
    HashAlgorithm
    object instance, when the OID of used hash algorithm is written in
    signature?

    If my assumptions are right, then VerifyData needs only buffer and
    signature. It can decode
    OID of used hash algorithm from a signature and compute hash with apropriate
    HashAlgorithm.

    Can anybody clarify that to me?

    Thanks.

    Marian


  • Pieter Philippaerts

    #2
    Re: RSACryptoServic eProvider.Verif y*

    "Marian Dvorsky" <marian@step.sk > wrote in message[color=blue]
    > What is not clear to me is, why the second method (VerifyHash()) needs OID
    > of used hash algorithm.[/color]

    This is because the underlying CryptoAPI doesn't allow signing arbitrary
    byte arrays. In fact, the CryptVerifySign ature requires that you pass in a
    valid HCRYPTHASH handle instead. The RSACryptoServic eProvider uses the OID
    to create a HCRYPTHASH handle that can be passed to the CryptVerifySign ature
    method.
    [color=blue]
    > Probably, it is used to compare it to the OID saved in a
    > signature.[/color]

    The signature does not contain an OID.

    Regards,
    Pieter Philippaerts
    Managed SSL/TLS: http://www.mentalis.org/go.php?sl


    Comment

    Working...