Replicating "openssl dgst" in Postman

Viewed 358

I am trying to sign requests sent with Postman in a pre-request script. Currently I am able to manually generate the signature (the "digest") using this shell command:

openssl dgst -sha256 -sign privateKey.pem < payload.txt | openssl base64

payload.txt contains the JSON payload to be signed. The output is a signature like this one: MCwCFBxtf5UnNnpYW+4DaaNFBD/0+pu+AhQ54vSnoeoe/smGIySUD1FFra/mpQ==

It seems that Postman scripts only implement a few JS libraries, and notably CryptoJS (source here), so I tried to replicate the previous OpenSSL command with CryptoJS.

This is what I ended up with:

var privateKey = environment['privateKey'];
var payload = request.data;
var hashDigest = CryptoJS.SHA256(payload);
var hmacDigest = CryptoJS.HmacSHA256(hashDigest, privateKey);
var sig = CryptoJS.enc.Base64.stringify(hmacDigest);
pm.environment.set("signature", sig);

But this script does not yield a working signature like the OpenSSL command. In fact the format are different: not the same length, and CryptoJS's one is deterministic, whereas OpenSSL's one is not.

Would you have some clue?

0 Answers
Related