While we are trying to subscribe one of the SNS topic we are getting signature validation failed.
Basically we are calling sig.verify(Base64.getDecoder().decode(message.getSignature())); and
here we are getting false as response. In result validation of signature is getting failed.
We checked with SNS topic in AWS console but could not find any issue there.
Below is the piece of code we used to get access over SNS. ( Role based access ) ->
snsClient = AmazonSNSClientBuilder.standard().withRegion(awsRegionName).withCredentials(new InstanceProfileCredentialsProvider(true)).build();
Below code is used to validate the certificate.
URL url = new URL(message.getSignatureCertURL());
logger.debug("SnsClient.isMessageSignatureValid:: [url -> {} ] ", url.toURI().toString());
InputStream inStream = url.openStream();
CertificateFactory cf = CertificateFactory.getInstance("X.509");
X509Certificate cert = (X509Certificate) cf.generateCertificate(inStream);
inStream.close();
Signature sig = Signature.getInstance("SHA1withRSA");
sig.initVerify(cert.getPublicKey());
sig.update(getMessageBytesToSign(message));
logger.debug("SnsClient.isMessageSignatureValid:: [getMessageBytesToSign -> {} ] ",
getMessageBytesToSign(message));
logger.debug("SnsClient.isMessageSignatureValid:: [sig -> {} ] ",
sig);
logger.debug("SnsClient.isMessageSignatureValid:: [isMessageSignatureValid boolean-> {}] ",
sig.verify(Base64.getDecoder()
.decode(message.getSignature())));
logger.debug("SnsClient.isMessageSignatureValid:: [isMessageSignatureValid -> {}] ",
Base64.getDecoder()
.decode(message.getSignature()));
return sig.verify(Base64.getDecoder()
.decode(message.getSignature()));