基于Botan C++库加载RSA私钥实现license.ini签名验证问询
使用Botan C++库实现license.ini的RSA-PKCS#1 v1.5签名与验证
我基于你提到的需求,整理了一套完整的实现方案,包含文件内容读取、RSA签名生成以及签名验证的全流程,每一步都做了详细注释,方便你参考:
完整代码实现
#include <Botan/RSA.h> #include <Botan/PK_Signer.h> #include <Botan/PK_Verifier.h> #include <Botan/auto_rng.h> #include <Botan/hex.h> #include <fstream> #include <string> #include <vector> // 读取文件内容的辅助函数 std::string readFileContent(const std::string& filePath) { std::ifstream file(filePath, std::ios::binary); if (!file.is_open()) { throw std::runtime_error("Failed to open file: " + filePath); } return std::string((std::istreambuf_iterator<char>(file)), std::istreambuf_iterator<char>()); } int main(int argc, char* argv[]) { if (argc < 2) { std::cerr << "Usage: " << argv[0] << " <path_to_license.ini>" << std::endl; return 1; } try { // -------------------------- 签名流程 -------------------------- // 1. 读取待签名的license文件内容 std::string licensePath = argv[1]; std::string fileContents = readFileContent(licensePath); // 2. 加载RSA私钥(注意:实际项目中请勿硬编码私钥,建议从加密文件/密钥管理系统读取) const uint8_t private_key[] = "你的RSA私钥内容(PEM格式)"; Botan::DataSource_Memory priv_key_src(private_key, sizeof(private_key) - 1); std::unique_ptr<Botan::Private_Key> rsa_priv_key(Botan::PKCS8::load_key(priv_key_src)); // 3. 初始化签名器:采用RSA+PKCS#1 v1.5填充,搭配SHA-256哈希算法 Botan::AutoSeeded_RNG rng; Botan::PK_Signer signer(*rsa_priv_key, rng, "SHA-256/PKCS1v15"); // 4. 对文件内容进行签名 signer.update(reinterpret_cast<const uint8_t*>(fileContents.data()), fileContents.size()); Botan::secure_vector<uint8_t> signature = signer.signature(rng); // 可选:将签名转换为十六进制字符串方便存储/传输 std::string signature_hex = Botan::hex_encode(signature); std::cout << "Generated signature (hex): " << signature_hex << std::endl; // -------------------------- 验证流程 -------------------------- // 1. 加载RSA公钥(同样建议从安全渠道读取,而非硬编码) const uint8_t public_key[] = "你的RSA公钥内容(PEM格式)"; Botan::DataSource_Memory pub_key_src(public_key, sizeof(public_key) - 1); std::unique_ptr<Botan::Public_Key> rsa_pub_key(Botan::X509::load_key(pub_key_src)); // 2. 初始化验证器:与签名流程使用相同的哈希算法和填充方式 Botan::PK_Verifier verifier(*rsa_pub_key, "SHA-256/PKCS1v15"); // 3. 验证签名 verifier.update(reinterpret_cast<const uint8_t*>(fileContents.data()), fileContents.size()); bool is_valid = verifier.check_signature(signature); if (is_valid) { std::cout << "Signature verification passed! License is authentic." << std::endl; } else { std::cerr << "Signature verification failed! License may be tampered." << std::endl; } } catch (const std::exception& e) { std::cerr << "Error: " << e.what() << std::endl; return 1; } return 0; }
关键注意事项
- 密钥安全:绝对不要在代码中硬编码私钥,实际项目中建议使用加密的密钥文件,或者借助专业的密钥管理服务来加载密钥,防止私钥泄露。
- 哈希算法选择:示例中使用SHA-256,这是当前安全性较高的选择;如果必须兼容旧系统,可替换为SHA-1,但SHA-1已被证实存在安全漏洞,不推荐。
- 填充方式匹配:签名和验证必须使用完全一致的填充方式和哈希算法,否则验证一定会失败。这里我们明确指定
SHA-256/PKCS1v15,确保两端配置统一。 - 异常处理:Botan库在操作失败时会抛出异常,务必做好异常捕获和处理,避免程序崩溃。
内容的提问来源于stack exchange,提问作者Petar Mijović
相关产品推荐
相关产品推荐

