I'm generating a pair of asymetric keys with nodejs crypto and using the sign and verify for my api calls. When I run the code locally (generating the keys, creating signature and then triggering an api function with the signature passed in) it passes the verification function. However, once it was put on the aws cloud and run as a lambda, it fails the verification every time. I'm generating the keys through a postman request to the serverless api which triggers my create keys lambda, then running the signature creation locally and then sending a request with the signature through postman to the endpoint which should verify it.
Here's how I am generating the signature
const sign = crypto.createSign('SHA256');
sign.update(Buffer.from(JSON.stringify(data)));
sign.end();
const signature = sign.sign(Buffer.from(privateKey), 'base64')
return signature;
Here's the verification:
let verifier = crypto.createVerify(
"sha256"
);
verifier.update(Buffer.from(JSON.stringify(data)));
verifier.end();
//verify signature
const verified = verifier.verify(publicKey, signature, 'base64')
The data being passed in is an object containing nonce, timestamp, and uuid.
I can't seem to see where I am going wrong, any insights would be helpful.