如何用OpenSSL从签名提取哈希?rsautl弃用后pkeyutl报错求正确命令
使用OpenSSL从签名文件提取哈希的正确命令
你尝试用以下rsautl命令从签名文件提取哈希:
openssl rsautl -verify -in SignS -pubin -inkey ServerPubKey -out HashRetrieved
其中SignS为签名文件,ServerPubKey为公钥,HashRetrieved是输出的哈希文件,但收到版本弃用提示:
The command rsautl was deprecated in version 3.0. Use 'pkeyutl' instead.
改用pkeyutl命令后:
openssl pkeyutl -verify -in SignS -pubin -inkey ServerPubKey -out HashRetrieved
又出现错误:
pkeyutl: No signature file specified for verify
正确命令说明
pkeyutl的-verify模式中,-in参数用于指定原始数据文件,而非签名文件;签名文件需要通过-sigfile参数指定。
基础正确命令:
openssl pkeyutl -verify -pubin -inkey ServerPubKey -sigfile SignS -out HashRetrieved
如果OpenSSL无法自动识别签名使用的摘要算法,可通过-digest参数指定(例如SHA256):
openssl pkeyutl -verify -pubin -inkey ServerPubKey -sigfile SignS -out HashRetrieved -digest sha256
执行该命令后,验证通过的哈希会输出到HashRetrieved文件中。
内容的提问来源于stack exchange,提问作者clemdcz
相关产品推荐
相关产品推荐

