llVerifyRSA
function
Function syntax
integer llVerifyRSA(string public_key,// PEM-formatted public key to use for signature verification.string msg,// Message string that was signed.string signature,// Base64-encoded signature to verify.string algorithm// Cryptographic digest algorithm to use.
);- Returns
integer- Energy
- 10
This function supports sha1, sha224, sha256, sha384, sha512 for algorithm.
Whitespace and newlines are ignored for public_key.
Returns an integer indicating whether the RSA signature is valid for msg when using hash algorithm algorithm and public RSA key public_key. Returns TRUE if the signature is verified, and FALSE otherwise. Use llSignRSA to generate signature. Combined, the two functions can generate and verify signed messages.
integer result = llVerifyRSA("", "", "", "");Caveats
Section titled “Caveats”- Despite its 50-byte cost (100 in Mono), if private_key does not include the “-----BEGIN PUBLIC KEY-----” header and “-----END PUBLIC KEY-----” footer, this function will throw a non-fatal error, “
llVerifyRSA: failed to import public key”, and returnFALSE. - Any invalid algorithm will throw a non-fatal error, “
llVerifyRSAvalid algorithms are: sha1, sha224, sha256, sha384, sha512”, and returnFALSE.
Examples
Section titled “Examples”Example 1
44 collapsed lines
// Generate an signature, then immediately verify if it is valid.
default{ state_entry() { // Key pair generated using LibreSSL 3.3.6 // For demonstration purposes only string private_key = "-----BEGIN RSA PRIVATE KEY-----MIIEogIBAAKCAQEAqxXSIhFHzYO9UNEUvMMXwhB4vf32fPirCxxV/w4m88jKPmFHQQe9DOwj7illmvg+81vzBNGt+uNYy/2zFegUtwvxKCEioeoanRpPcvn9r/d/kXadWL/DyKJwHbF1EtTfPAZSl6ZIBIYis8HQ/RAln3olS705AmCKBRkbz3cZ+dTzqX1v7ohqqPPoCaXQFgLTMYnqU8ZTsq1Sl8BwKK735HPmKLCEjZaMn97lvzGHufY/JdRsdwdRHqKnpe2w2c0AzNpQtjoRCnPtj7cFgCeztjAcbdtuS8ipJTEIuBLWHCVVXIlDDQ6jJvIEW7tt+6kde/NUskRASd7Rtoy5AeS7cwIDAQABAoIBABwvix/7stWj55Oh7oWuqoJZTlsWtP4fxaYd8/kCLt6o7NDcG+4VxUqUuNKq1UdzsINNWbsohD46KE3rLQ7l3kvN1twioV8Ff370b7RkhSvxXX3sib2uUiYCxO/PZZdFpMVx0TeUuHauVpdAzhpzB4+/gtd4hCTlHLf8S/2hBJGJA9e37Vo3MqXh43QRFTD8pgjb0mUWa4xJeZlz3vGmQl0uMS04wX+r7Pq1HKs7gk93WeLrNhEQgRwUPgumrMGHey9eF1kDb14m3O7ZqWU7MWWME2lxcUV0YT/iHPfvStvLHiEdi1z2TGKkMmlHX7RGpk7Js5GGQfeEKEsvihXuFmkCgYEA2y6V2+HCmViA8V1qY907z5dvG3ar9zbm3qfcJDJFoNOzDZNU0NRJeZu/LhwTHW7PArAuWhxh7ENu9Bhl5FjvMuyqrMPud1Tf0GsrYKQJITgbW6IC6w/Na+2ZMm6VDCztS5MNNmWRCTTEecd4lnPLfyX9XYfUvUovzv5mM65Hzl0CgYEAx9LyRR1tkjgiIJHmpv95MkaHg4O4NZT0eiyykRz1qENESZOtJ00l+/p4vZSOdQjwPl+qvjMhlZc9a2292UEy3BsBOPB/nJybLXBDFa0KYUCc3/aHGSgq+ZbUKNhdBq2c83hbDpw2ajHluLtXO7D4kDGvEDLPN+/19NElI6EL9A8CgYAVRu5xS/cyH69UvvbG/wEBY/f7OIf1FbVPxAfQ07iCpkppdPX018bSMVZbyYnpf4pE/olhYgP3hYxN0diCVEfUL7lZ0CNkHi8j8mNhnErumJ2/RXj3DK+qXIRUqvt5FRtsDLhpoW508FRqZfzEzjThAPUZkUgLoBoIBBYzyiVaWQKBgD3GvHmbmHVc/0f8c0drsedWIK0K+tct3ssqqGXugw/rA+CPVDfTRQv6qntJwyTxh3xxDRNSMW7S2/0rZ0cUPgoIGz+kMn+TdvH8Q/Eelxfr5tPinm+rmGWjOKIMCe53nA81RUlmB/iaxn9vA5ADrUS+53Vlj+SmPe7a/dVfA5gHAoGAbS4sMlUkUd449PT33rqx26aNKkKLI9PLxgWE7YBfwzaUkG0MBryQqP5LaIY2a+8ZvUeHxmY0oQfPQkH5KKbAaC0ozaXf+3qX0Gfkt8vxsh41ON5esr0tfcm2BFdQrdBOACefo2kOFfdMSP6KWKI3HZMJAr9SDcAiL23IQZ/wl/c=-----END RSA PRIVATE KEY-----";
string public_key = "-----BEGIN PUBLIC KEY-----MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqxXSIhFHzYO9UNEUvMMXwhB4vf32fPirCxxV/w4m88jKPmFHQQe9DOwj7illmvg+81vzBNGt+uNYy/2zFegUtwvxKCEioeoanRpPcvn9r/d/kXadWL/DyKJwHbF1EtTfPAZSl6ZIBIYis8HQ/RAln3olS705AmCKBRkbz3cZ+dTzqX1v7ohqqPPoCaXQFgLTMYnqU8ZTsq1Sl8BwKK735HPmKLCEjZaMn97lvzGHufY/JdRsdwdRHqKnpe2w2c0AzNpQtjoRCnPtj7cFgCeztjAcbdtuS8ipJTEIuBLWHCVVXIlDDQ6jJvIEW7tt+6kde/NUskRASd7Rtoy5AeS7cwIDAQAB-----END PUBLIC KEY-----";
// Supported algorithims for llVerifyRSA() include: // sha1, sha224, sha256, sha384, sha512
13 collapsed lines
string algorithm = "sha1"; string msg = "Hello, Avatar!";
string signature = llSignRSA(private_key, msg, algorithm);
// For the given private_key/msg/algorithm, expect the signature // to resemble 'SgqafXI/M70FJr5th0VR3U36L...O76Bg==' llSay(0, "RSA signature of message '" + msg + "' using algorithm " + algorithm + " is " + signature);
/* Now, imagine that msg and signature were transmitted to another script over chat or similar. The other script has access to public_key but not to private_key, but can still verify the authenticity of msg using the signature. */
integer valid_signature = llVerifyRSA(public_key, msg, signature, algorithm);
if(valid_signature)9 collapsed lines
{ llSay(0, "Signature verified successfully!"); } else { llSay(0, "Signature verification failed!"); } }}- If you do not have an RSA key pair you wish to use already, you can easily generate an RSA key pair using this generator.
See also
Section titled “See also”Functions
Section titled “Functions”Original wiki source
Some wiki templates and tables need their original context. View this article on the Second Life Wiki. Technical wording and examples are retained from the source; historical guidance may differ from current behavior.