-
Notifications
You must be signed in to change notification settings - Fork 24
/
sign_pss.go
64 lines (49 loc) · 1.34 KB
/
sign_pss.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
package rsa
import (
"errors"
"crypto/rsa"
"crypto/rand"
)
// 私钥签名
// 常用为: PS256[SHA256] | PS384[SHA384] | PS512[SHA512]
func (this RSA) SignPSS(opts ...rsa.PSSOptions) RSA {
if this.privateKey == nil {
err := errors.New("privateKey error.")
return this.AppendError(err)
}
h := this.signHash.New()
h.Write(this.data)
hashed := h.Sum(nil)
options := rsa.PSSOptions{
SaltLength: rsa.PSSSaltLengthEqualsHash,
}
if len(opts) > 0 {
options = opts[0]
}
parsedData, err := rsa.SignPSS(rand.Reader, this.privateKey, this.signHash, hashed, &options)
this.parsedData = parsedData
return this.AppendError(err)
}
// 公钥验证
// 使用原始数据[data]对比签名后数据
func (this RSA) VerifyPSS(data []byte, opts ...rsa.PSSOptions) RSA {
if this.publicKey == nil {
err := errors.New("publicKey error.")
return this.AppendError(err)
}
h := this.signHash.New()
h.Write(data)
hashed := h.Sum(nil)
options := rsa.PSSOptions{
SaltLength: rsa.PSSSaltLengthAuto,
}
if len(opts) > 0 {
options = opts[0]
}
err := rsa.VerifyPSS(this.publicKey, this.signHash, hashed, this.data, &options)
if err != nil {
return this.AppendError(err)
}
this.verify = true
return this
}