Google AMP:如何用私钥签名update-cache请求及命令执行问题
Got it, let's troubleshoot why your OpenSSL command is failing and get that binary RSA signature generated correctly. The core issue here is a syntax error in your original command—you're combining the echo and cat operations incorrectly without proper separation, which confuses the shell.
What's Wrong With the Original Command?
Your original line tries to run echo -n >url.txt '/update-cache/...' cat url.txt as a single command, which makes the shell treat cat and url.txt as extra arguments to echo instead of running them as a separate step. This breaks the pipeline and triggers the error you're seeing.
Corrected Command Options
Here are two reliable ways to generate the valid signature:
Option 1: Using a Temporary File (Matching the Original Workflow)
Split the command into two clear steps (or combine them safely with a semicolon):
# Step 1: Write the exact URL string to url.txt (no extra newlines) echo -n '/update-cache/c/s/example.com/article?amp_action=flush&amp_ts=1484941817' > url.txt # Step 2: Sign the file content with your private key cat url.txt | openssl dgst -sha256 -sign private-key.pem > signature.bin
Or as a single line:
echo -n '/update-cache/c/s/example.com/article?amp_action=flush&amp_ts=1484941817' > url.txt ; cat url.txt | openssl dgst -sha256 -sign private-key.pem > signature.bin
Option 2: Skip the Temporary File (More Efficient)
You can pipe the URL string directly to OpenSSL without writing to a file first—this avoids any potential issues with file permissions or accidental newline additions:
echo -n '/update-cache/c/s/example.com/article?amp_action=flush&amp_ts=1484941817' | openssl dgst -sha256 -sign private-key.pem > signature.bin
Critical Notes to Avoid Invalid Signatures
- Don't skip the
-nflag: This ensuresechodoesn't append a trailing newline to the URL. The signature is generated for the exact string in the request, so extra characters will make it invalid. - Verify your private key: Make sure
private-key.pemis a valid PEM-formatted RSA private key. If you have a DER-formatted key, convert it first withopenssl rsa -inform der -in private-key.der -out private-key.pem. - Password-protected keys: If your private key has a passphrase, OpenSSL will prompt you to enter it—this is expected behavior, just input the correct password to proceed.
内容的提问来源于stack exchange,提问作者Adam

