From: GOTOU Yuuzou Date: 2004-07-02T15:16:02+09:00 Subject: Re: Another Ruby/OpenSSL Patch In message <40E46DA4.2010105@email.byu.edu>, `Jamis Buck ' wrote: > I've attached a patch. With the addition of the DSA#do_verify method > that this patch exposes, Net::SSH can now successfully handle ssh-dss > server keys. I think these methods can be written with existing library. Could you try the attached code? -- gotoyuzo require "openssl" class OpenSSL::PKey::DSA def do_sign(data) sig = sign(OpenSSL::Digest::DSS1.new, data) a1sig = OpenSSL::ASN1.decode(sig) sig_r = sprintf("%.40x", a1sig.value[0].value) sig_s = sprintf("%.40x", a1sig.value[1].value) if sig_r.length > 40 || sig_s.length > 40 raise OpenSSL::PKey::DSAError, "bad sig size" end return [sig_r].pack("H*") + [sig_s].pack("H*") end def do_verify(sig, data) sig_r = sig[0,20].unpack("H*")[0].to_i(16) sig_s = sig[20,20].unpack("H*")[0].to_i(16) a1sig = OpenSSL::ASN1::Sequence([ OpenSSL::ASN1::Integer(sig_r), OpenSSL::ASN1::Integer(sig_s) ]) return verify(OpenSSL::Digest::DSS1.new, a1sig.to_der, data) end end dsa = OpenSSL::PKey::DSA.new(512) data = File.read(__FILE__) sig = dsa.do_sign(data) p dsa.do_verify(sig, data)