在我的静态库中,我有一个许可证文件。我想确保它是由我自己生成的(并且没有被更改)。所以我的想法是使用我读过的 RSA 签名。


第一:使用我找到的信息生成私钥和自签名证书here https://github.com/superwills/iOSRSAPublicKeyEncryption.

// Generate private key
openssl genrsa -out private_key.pem 2048 -sha256

// Generate certificate request
openssl req -new -key private_key.pem -out certificate_request.pem -sha256

// Generate public certificate
openssl x509 -req -days 2000 -in certificate_request.pem -signkey private_key.pem -out certificate.pem -sha256

// Convert it to cer format so iOS kan work with it
openssl x509 -outform der -in certificate.pem -out certificate.cer -sha256

之后,我创建一个许可证文件(以日期和应用程序标识符作为内容)并根据找到的信息为该文件生成签名here https://stackoverflow.com/questions/10782826/digital-signature-for-a-file-using-openssl:

// Store the sha256 of the licence in a file
openssl dgst -sha256 licence.txt > hash

// And generate a signature file for that hash with the private key generated earlier
openssl rsautl -sign -inkey private_key.pem -keyform PEM -in hash > signature.sig


接下来我复制certificate.cer, signature.sig and license.txt到我的应用程序。


The Seucyrity.Framework我发现使用了SecKeyRef引用 RSA 密钥/证书和SecKeyRawVerify验证签名。


- (SecKeyRef)publicKeyFromFile:(NSString *) path
    NSData *myCertData = [[NSFileManager defaultManager] contentsAtPath:path];
    CFDataRef myCertDataRef = (__bridge CFDataRef) myCertData;

    SecCertificateRef cert = SecCertificateCreateWithData (kCFAllocatorDefault, myCertDataRef);
    CFArrayRef certs = CFArrayCreate(kCFAllocatorDefault, (const void **) &cert, 1, NULL);
    SecPolicyRef policy = SecPolicyCreateBasicX509();
    SecTrustRef trust;
    SecTrustCreateWithCertificates(certs, policy, &trust);
    SecTrustResultType trustResult;
    SecTrustEvaluate(trust, &trustResult);
    SecKeyRef pub_key_leaf = SecTrustCopyPublicKey(trust);

    if (trustResult == kSecTrustResultRecoverableTrustFailure)
        NSLog(@"I think this is the problem");
    return pub_key_leaf;

这是基于this https://stackoverflow.com/questions/1595013/iphone-how-to-create-a-seckeyref-from-a-public-key-file-pem所以帖子。


BOOL PKCSVerifyBytesSHA256withRSA(NSData* plainData, NSData* signature, SecKeyRef publicKey)
    size_t signedHashBytesSize = SecKeyGetBlockSize(publicKey);
    const void* signedHashBytes = [signature bytes];

    size_t hashBytesSize = CC_SHA256_DIGEST_LENGTH;
    uint8_t* hashBytes = malloc(hashBytesSize);
    if (!CC_SHA256([plainData bytes], (CC_LONG)[plainData length], hashBytes)) {
        return nil;

    OSStatus status = SecKeyRawVerify(publicKey,

    return status == errSecSuccess;

这是取自here https://stackoverflow.com/questions/21724337/signing-and-verifying-on-ios-using-rsa


// Get the licence data
NSString *licencePath = [[NSBundle mainBundle] pathForResource:@"licence" ofType:@"txt"];
NSData *data = [[NSFileManager defaultManager] contentsAtPath:licencePath];

// Get the signature data
NSString *signaturePath = [[NSBundle mainBundle] pathForResource:@"signature" ofType:@"sig"];
NSData *signature = [[NSFileManager defaultManager] contentsAtPath:signaturePath];

// Get the public key
NSString *publicKeyPath = [[NSBundle mainBundle] pathForResource:@"certificate" ofType:@"cer"];
SecKeyRef publicKey = [self publicKeyFromFile:publicKeyPath];

// Check if the signature is valid with this public key for this data
BOOL result = PKCSVerifyBytesSHA256withRSA(data, signature, publicKey);

if (result)
    NSLog(@"Alright All good!");
    NSLog(@"Something went wrong!");

目前它总是说:“出了点问题!”虽然我不确定是什么。我发现获取公钥的方法的信任结果等于kSecTrustResultRecoverableTrustFailure我认为这就是问题所在。在里面苹果文档 https://developer.apple.com/library/ios/documentation/Security/Conceptual/CertKeyTrustProgGuide/03tasks/tasks.html我发现这可能是证书已过期的结果。尽管这里的情况似乎并非如此。但也许我生成证书的方式有问题?


I have uploaded http://up.indev.nl/RTR4y0Ou0L.zip具有生成的证书和此处引用的代码的 iOS 项目。也许这会派上用场。

问题出在你创建签名文件的方式上;按照相同的步骤,我能够生成等效的二进制文件signature.sig file.

通过查看内部hash在文件中我们可以看到 openssl 添加了一些前缀(并对哈希值进行了十六进制编码):

$ cat hash
SHA256(licence.txt)= 652b23d424dd7106b66f14c49bac5013c74724c055bc2711521a1ddf23441724

So signature.sig是基于此而不是基于license.txt


openssl dgst -sha256 -sign certificates/private_key.pem licence.txt > signature.sig

哈希和签名步骤正确,示例输出:Alright All good!


- (SecKeyRef)publicKeyFromFile:(NSString *) path
    NSData * certificateData = [[NSFileManager defaultManager] contentsAtPath:path];
    SecCertificateRef certificateFromFile = SecCertificateCreateWithData(NULL, (__bridge CFDataRef)certificateData);
    SecPolicyRef secPolicy = SecPolicyCreateBasicX509();
    SecTrustRef trust;
    SecTrustCreateWithCertificates( certificateFromFile, secPolicy, &trust);
    SecTrustResultType resultType;
    SecTrustEvaluate(trust, &resultType);
    SecKeyRef publicKey = SecTrustCopyPublicKey(trust);
    return publicKey;

BOOL PKCSVerifyBytesSHA256withRSA(NSData* plainData, NSData* signature, SecKeyRef publicKey)
    uint8_t digest[CC_SHA256_DIGEST_LENGTH];
    if (!CC_SHA256([plainData bytes], (CC_LONG)[plainData length], digest))
        return NO;

    OSStatus status = SecKeyRawVerify(publicKey,
                                      [signature bytes],
                                      [signature length]);

    return status == errSecSuccess;

PS: the malloc是泄漏


为了让你现在的signature.sig文件按原样工作,您必须执行与 openssl 相同的步骤(添加前缀、十六进制哈希和换行符\n),然后将此数据传递给SecKeyRawVerify with kSecPaddingPKCS1并不是kSecPaddingPKCS1SHA256:

BOOL PKCSVerifyBytesSHA256withRSA(NSData* plainData, NSData* signature, SecKeyRef publicKey)
    uint8_t digest[CC_SHA256_DIGEST_LENGTH];
    if (!CC_SHA256([plainData bytes], (CC_LONG)[plainData length], digest))
        return NO;

    NSMutableString *hashFile = [NSMutableString stringWithFormat:@"SHA256(licence.txt)= "];
    for (NSUInteger index = 0; index < sizeof(digest); ++index)
        [hashFile appendFormat:@"%02x", digest[index]];

    [hashFile appendString:@"\n"];
    NSData *hashFileData = [hashFile dataUsingEncoding:NSNonLossyASCIIStringEncoding];

    OSStatus status = SecKeyRawVerify(publicKey,
                                      [hashFileData bytes],
                                      [hashFileData length],
                                      [signature bytes],
                                      [signature length]);

    return status == errSecSuccess;

