I'm not familiar with cryptography or the PKCS protocol, but what i need is to crypto.verify succesfully in NodeJS using singature generated in MSSQL signbycert.
by using this as reference: https://stackoverflow.com/a/77519242/19991312, with the following value:
DECLARE @PlainText as varchar(max) = 'Hello World';
DECLARE @Signature as varbinary(max);
SET @Signature = SignByCert(Cert_ID('MyTestCertificate'), @PlainText);
SELECT @Signature as SIG, CERTENCODED(Cert_ID('MyTestCertificate')) as PBK;
plain text
Hello World
Signature
01000502040000002B0DFBF8B0EB048B18BA30A7A9AC3C63C18D8F932DC974178C61F810758A3FB81F14247AA338E6DBABAE265A8D8077C689901E33B016379685F7A0D27429DCB78F438201F5C04827F2F2B816BF5EFD569FA2AD7EEECC69621AF5F7C39893F0001FC22EAA74DB0F5026CDB38F5BFF3A3D208196C75E7A7A9556050459C826194E460D4C5AB1F30ACFF8594E4E99BC8FD5C8675E79EC54AC9EB017FA112C1759BF387C248869C461677E1CF711860618BFCAC1332C879C01D88C0EBFD584BCF4B358D5D47618A7367DE3A1943AB18454D1B8C423437661120EEE2225A35F763002E9AC80B23B5F03F1EA4C16422BEA8C51032AA0C16B73C7AC5583496EDFD6AA21
public key

Based on my rough understanding after reading this: https://stackoverflow.com/a/77519242/19991312, is that MSSQL signature is different from the standard PKCS protocol and cannot be directly used in crypto.verify
so i did some rough transformation on the signature value, but still could not verify the signature, possibly due to my misunderstand or lack of knowledge regarding cryptography. My current verification in nodeJS as follow:
const plainText = 'Hello World';
const textDigest = crypto.hash('sha256', plainText, 'hex');
const sqlSignature = '...';
const pbk = '...';
const x509Cert = new crypto.X509Certificate(Buffer.from(pbk, 'hex'))
const signatureTransform = Buffer.from(sqlSignature.slice(16), 'hex').reverse()
const isSignatureValid = crypto.verify(null, Buffer.from(textDigest, 'hex'), x509Cert.publicKey, signatureTransform)
console.log('isSignatureValid', isSignatureValid ) // false Q^Q
As already described in the linked post, signatureTransform
is not compatible with the PKCS#1 v1.5 signature scheme (more precisely with the RSASSA-PKCS1-v1_5 signature scheme), because the applied encoding differs from EMSA-PKCS1-v1_5 in that only the hashed data and not the DER encoding of the DigestInfo value was used.
For this reason, crypto.verify()
must not be applied, as this checks whether the decrypted data strictly conforms to the EMSA-PKCS1-v1_5 encoding and, in particular, whether the hash portion matches the hashed message.
Instead, crypto.publicDecrypt()
should be used. This implementation performs a pure decryption with the public key and an unpadding of the static part (0x0001FF...FF00) without further checking of the resulting data, and therefore returns the message hash here.
Thus, verification simply consists of checking that the hashes are identical:
...
const decrypted = crypto.publicDecrypt(x509Cert.publicKey, signatureTransform).toString('hex')
const verified = (decrypted === textDigest)
console.log("Verified:" , verified) // Verified: true