I have a signature that was issued by a java service like this:
File file = new File("<path-to-private-key>");
FileInputStream fileInputStream = new FileInputStream(file);
byte[] bytes = new byte[(int) file.length()];
fileInputStream.read(bytes);
String key = new String(bytes, Charset.defaultCharset());
key = key
.replace("-----BEGIN PRIVATE KEY-----", "")
.replace("-----END PRIVATE KEY-----", "")
.replace("\r\n", "")
.replace("\n", "")
.replace(" ", "");
KeyFactory keyFactory = KeyFactory.getInstance("RSA");
PKCS8EncodedKeySpec keySpec = new PKCS8EncodedKeySpec(Base64.getDecoder().decode(key));
RSAPrivateKey privateKey = (RSAPrivateKey) keyFactory.generatePrivate(keySpec);
Signature signer = Signature.getInstance("RSASSA-PSS");
signer.setParameter(new PSSParameterSpec("SHA-512", "MGF1", MGF1ParameterSpec.SHA512, 64, 1));
signer.initSign(privateKey);
signer.update(message.getBytes(StandardCharsets.UTF_8));
byte[] byteArraySignature = signer.sign();
signature = encoder.encodeToString(message);
And then I have a .net service that verifies it like this:
var fileStream = File.OpenText("<path-to-public-key>");
var pemReader = new PemReader(fileStream);
var publicKey = ((Org.BouncyCastle.X509.X509Certificate)pemReader.ReadObject()).GetPublicKey();
var signer = new PssSigner(new RsaEngine(), new Sha512Digest(), 64);
signer.Init(false, (RsaKeyParameters)publicKey);
var bytes = UTF8.GetBytes(message);
signer.BlockUpdate(bytes, 0, bytes.Length);
var isvalid = signer.VerifySignature(Convert.FromBase64String(signature));
the problem is that .net service says the signature is invalid. Any ideas what I am doing wrong?
I also tried this:
var publicKey = certificate.GetRSAPublicKey();
var isValid = publicKey.VerifyData(UTF8.GetBytes(message), Convert.FromBase64String(signature), HashAlgorithmName.SHA512, RSASignaturePadding.Pss);
Is there any configuration difference between c# and Java I am not aware of?