Powerbuilder 9.0.3/12.6中Chilkat RSASSA-PSS签名无法通过Isabel API验证的参数配置排查请求
Hey there, let's walk through your problem and fix the issues preventing your signature from passing Isabel's API validation.
1. Your Chilkat RSA Configuration is Incorrect
First off, the way you're enabling RSASSA-PSS is wrong. The OaepPadding property is used for RSA encryption with OAEP padding, not for PSS signature padding. That's a critical mix-up. Here's how you should configure Chilkat to match Isabel's requirements:
Corrected PowerBuilder Code
loo_Rsa = create oleobject li_rc = loo_Rsa.ConnectToNewObject("Chilkat_9_5_0.Rsa") loo_Rsa.DebugLogFilePath = "c:\tmp\rsa.log" loo_Rsa.VerboseLogging=1 li_Success=loo_Rsa.ImportPrivateKeyObj(loo_Privkey) if li_Success <> 1 then ls_error = "Error importPrivateKey: "+loo_Rsa.LastErrorText destroy loo_Rsa goto ee_error end if // Configure RSASSA-PSS signature parameters (matching Isabel's requirements) loo_Rsa.SignaturePadding = "PSS" // Enables PSS for signing (not OaepPadding) loo_Rsa.PssSaltLength = 32 // 32-byte salt (matches SHA-256 hash length) loo_Rsa.MgfHash = "SHA-256" // MGF1 uses SHA-256 as required loo_Rsa.EncodingMode = "base64" loo_Rsa.Charset = "utf-8" // Enforce UTF-8 per HTTP signature standards // Sign the string with SHA-256 hash (matches Isabel's hash algorithm) ls_Signature = loo_Rsa.SignStringENC(ls_signing_string,"SHA-256")
Isabel's requirements are fully addressed here:
- RSA-PSS with SHA-256 hash
- MGF1 using SHA-256
- 32-byte salt
- Trailer field 1 (Chilkat's default for PSS, no extra config needed)
2. The =3D in Your Logs is a Critical Red Flag
Looking at your Chilkat logs, the signing string is being mangled: characters like = are converted to =3D. That's quoted-printable encoding, which is completely unintended here. This means you're signing a modified version of the string Isabel expects—validation will always fail because of this mismatch.
Why This Happens & How to Fix It
- Check your input string: Ensure
ls_signing_stringis the raw, unencoded string you provided (no URL/QP encoding applied beforehand). - Fix character set: HTTP signatures require UTF-8 encoding, but your original code used Chilkat's default (likely
windows-1252). The corrected code above explicitly setsCharset = "utf-8"to avoid encoding mismatches. - Disable unwanted encoding: If your Chilkat version has a
QuotedPrintableproperty, set it to 0 to prevent automatic QP encoding of the input.
Compare the log's inputBytesQP section to your original signing string: you'll see offset=0 becomes offset=3D0 and == becomes =3D=3D—this is a key reason the signature is invalid.
3. Additional Validation Checks
Even with fixed config, double-check these details to rule out other issues:
- Newline format: Ensure your signing string uses single
\nline breaks, not Windows-style\r\n. Isabel's API likely enforces strict line ending rules. - Digest correctness: Verify your SHA-512 digest is computed correctly (base64-encoded hash of the request body, if any) and matches the format
SHA-512=<base64_hash>exactly. - Timestamp freshness: The
(created)timestamp must be a valid Unix timestamp within Isabel's allowed time window (usually a few minutes). Stale timestamps will trigger validation errors.
4. Test After Changes
After updating your code, re-run the request and check the Chilkat logs:
- Confirm the
inputBytesQPsection now matches your original signing string exactly (no=3Dreplacements) - Verify the signature is generated with the correct PSS parameters (look for
pss_encode: emLen: 256 autoSelectedSaltLen: 32andMgfHash: SHA-256in logs)
内容的提问来源于stack exchange,提问作者GuyL

