KMSインスタンスのSDKクライアントが初期化されると、クライアントを利用して、デジタル署名および署名検証用にそれぞれSignおよびVerify APIを呼び出すことができます。 このトピックでは、両方のプロセスのコードサンプルを示します。
完全なコード例
Sign APIを呼び出して非対称キーでデジタル署名を実行し、Verify APIを呼び出して非対称キーで署名検証を実行します。
ソースコードGitHubリポジトリ: SignVerify.php
コード例分析
クライアントの初期化
クライアントの初期化の詳細については、「クライアントの初期化」をご参照ください。
<?php
use AlibabaCloud\Dkms\Gcs\Sdk\Client as AlibabaCloudDkmsGcsSdkClient;
use AlibabaCloud\Dkms\Gcs\OpenApi\Models\Config as AlibabaCloudDkmsGcsOpenApiConfig;
function getDkmsGcsSdkClient()
{
global $clientKeyContent, $password, $endpoint;
// Construct the KMS instance SDK client configuration
$config = new AlibabaCloudDkmsGcsOpenApiConfig();
// The connection protocol. Set the value to https. The KMS instance service only allows access through the HTTPS protocol.
$config->protocol = 'https';
// Client Key.
$config->clientKeyContent = $clientKeyContent;
// Client Key security token.
$config->password = $password;
// The endpoint of your KMS instance. Set the value in the following format: <ID of your KMS instance >.cryptoservice.kms.aliyuncs.com.
$config->endpoint = $endpoint;
// Instance CA certificate
$config->caFilePath = 'path/to/caCert.pem';
// Construct the KMS instance SDK client object
return new AlibabaCloudDkmsGcsSdkClient($config);
}Sign APIを呼び出して、非対称キーを使用してデジタル署名を実行します。
/**
* Signing example
* @param AlibabaCloudDkmsGcsSdkClient $client
* @param string $keyId
* @param string $message
* @param string $messageType
* @param string $algorithm
* @return SignatureContext
*/
function signSample($client, $keyId, $message, $messageType, $algorithm) {
// Construct a signing request
$signRequest = new SignRequest();
$signRequest->keyId = $keyId;
$signRequest->algorithm = $algorithm;
$signRequest->message = AlibabaCloudTeaUtils::toBytes($message);
$signRequest->messageType = $messageType;
$runtimeOptions = new RuntimeOptions();
// Ignore the certificate
//$runtimeOptions->ignoreSSL = true;
try {
// Call the signing API to perform signing
$signResponse = $client->signWithOptions($signRequest, $runtimeOptions);
// Key ID
$keyId = $signResponse->keyId;
// Signature value
$signature = $signResponse->signature;
// Message type
$messageType = $signResponse->messageType;
// Signature algorithm
$algorithm = $signResponse->algorithm;
var_dump($signResponse->toMap());
return new SignatureContext([
'keyId' => $keyId,
'signature' => $signature,
'messageType' => $messageType,
'algorithm' => $algorithm
]);
} catch (Exception $error) {
if ($error instanceof \AlibabaCloud\Tea\Exception\TeaError) {
var_dump($error->getErrorInfo());
}
var_dump($error->getMessage());
var_dump($error->getTraceAsString());
}
return null;
}Verify APIを呼び出して、非対称キーを使用してデジタル署名を検証します。
/**
* Signature verification example
* @param AlibabaCloudDkmsGcsSdkClient $client
* @param string $message
* @param SignatureContext $ctx
* @return bool|null
*/
function verifySample($client, $message, $ctx) {
// Construct a signature verification request
$verifyRequest = new VerifyRequest();
$verifyRequest->keyId = $ctx->keyId;
$verifyRequest->signature = $ctx->signature;
$verifyRequest->message = AlibabaCloudTeaUtils::toBytes($message);
$verifyRequest->messageType = $ctx->messageType;
$verifyRequest->algorithm = $ctx->algorithm;
$runtimeOptions = new RuntimeOptions();
// Ignore the server certificate
//$runtimeOptions->ignoreSSL = true;
try {
// Call the signature verification API to perform verification
$verifyResponse = $client->verifyWithOptions($verifyRequest, $runtimeOptions);
// Verification result
$value = $verifyResponse->value;
var_dump($verifyResponse->toMap());
return $value;
} catch (Exception $error) {
if ($error instanceof \AlibabaCloud\Tea\Exception\TeaError) {
var_dump($error->getErrorInfo());
}
var_dump($error->getMessage());
var_dump($error->getTraceAsString());
}
return null;
}