From: Francis Cianfrocca Date: 2006-08-12T02:28:20+09:00 Subject: Re: Cryptographic Signatures: Ruby versus OpenSSL On 8/11/06, Andy Stewart wrote: > > That's perfect, thank you. > > I'll now go and dig through RSA::private_encrypt and RSA::sign and > see how they differ. > > Thank you also to Jan and Robert for your helpful comments. > > Kind regards, > Andy > > RSA#sign is basically a wrapper over EVP_SignInit, EVP_SignUpdate and EVP_SignFinalize, which are themselves a high-level wrapper over the actual crypto operations. The EVP_xxx calls do the hashing for you, so since you're using RSA, you have to specify a digest algorithm. rsautl -sign is a very dumb piece of code that only encrypts your plaintext with a private key. You notice in your shell pipeline, you did the sha digest yourself. That's what I did in the Ruby code I sent you. I assume you tested the Ruby output with rsautl -verify and it worked?