首页
学习
活动
专区
圈层
工具
发布
社区首页 >问答首页 >如何使用Python gnupg模块验证gnupg签名?

如何使用Python gnupg模块验证gnupg签名?
EN

Stack Overflow用户
提问于 2011-04-15 14:46:10
回答 1查看 6.3K关注 0票数 5

我对Python gnupg模块的验证签名有问题。通过这个模块,我可以对文件进行加密和签名:

代码语言:javascript
复制
gpg.encrypt_file(stream, encrypt_for, sign=sign_by, passphrase=key_passwd, output=file_out)

这样的加密文件可以通过命令行gpg解密,输出:

代码语言:javascript
复制
gpg: encrypted with 2048-bit ELG-E key, ID 518CD1AD, created 2011-04-14
            "client"
gpg: Signature made 04/14/11 13:36:14 using DSA key ID C7C006DD
gpg: Good signature from "server"

也可以用Python gnupg模块解密,输出文件有解密的内容,但无法验证签名。用于解密和验证的代码:

代码语言:javascript
复制
def decrypt_file(file_in, file_out, key_passwd):
    gpg = gnupg.GPG()
    f = open(file_in, "rb")
    data = f.read()
    f.close()
    gpg.decrypt(data, passphrase=key_passwd, output=file_out)
    verified = gpg.verify(data)
    if not verified:
        raise ValueError("Signature could not be verified!")

我得到的异常:

代码语言:javascript
复制
decrypting file...
Exception in thread Thread-12:
Traceback (most recent call last):
    File "c:\Python26\lib\threading.py", line 534, in __bootstrap_inner
        self.run()
    File "c:\Python26\lib\threading.py", line 486, in run
        self.__target(*self.__args, **self.__kwargs)
    File "c:\Python26\lib\site-packages\gnupg.py", line 202, in _read_response
        result.handle_status(keyword, value)
    File "c:\Python26\lib\site-packages\gnupg.py", line 731, in handle_status
        raise ValueError("Unknown status message: %r" % key)
ValueError: Unknown status message: u'UNEXPECTED'

Traceback (most recent call last):
    File "ht_gnupg.py", line 32, in <module>
        test()
    File "ht_gnupg.py", line 27, in test
        decrypt_file('test_p.enc', 'test_p.txt', 'client')
    File "ht_gnupg.py", line 18, in decrypt_file
        raise ValueError("Signature could not be verified!")
ValueError: Signature could not be verified!

我使用来自python-gnupg-0.2.7.win32.exegnupg-0.2.7和ActiveStatus Python2.6。

我也尝试过gpg.verify_file(),但我得到了同样的错误。文件是ASCII装甲的,看起来像:

代码语言:javascript
复制
-----BEGIN PGP MESSAGE-----
Version: GnuPG v1.4.9 (MingW32)

hQIOA0EAndRRjNGtEAf/YxMQaFMnBwT3Per6ypoMYaO1AKQikRgJJMJ90a/EoZ44
...
=G6Ai
-----END PGP MESSAGE-----

如何像命令行gpg一样验证签名

EN

回答 1

Stack Overflow用户

回答已采纳

发布于 2011-04-16 03:50:40

有关如何在解密时验证签名的示例脚本,请参阅this gist

代码(截至2011-04-05)如下:

代码语言:javascript
复制
from cStringIO import StringIO
import gnupg
import logging
import os
import shutil

def generate_key(gpg, first_name, last_name, domain, passphrase=None):
    "Generate a key"
    params = {
        'Key-Type': 'DSA',
        'Key-Length': 1024,
        'Subkey-Type': 'ELG-E',
        'Subkey-Length': 2048,
        'Name-Comment': 'A test user',
        'Expire-Date': 0,
    }
    params['Name-Real'] = '%s %s' % (first_name, last_name)
    params['Name-Email'] = ("%s.%s@%s" % (first_name, last_name, domain)).lower()
    if passphrase is None:
        passphrase = ("%s%s" % (first_name[0], last_name)).lower()
    params['Passphrase'] = passphrase
    cmd = gpg.gen_key_input(**params)
    return gpg.gen_key(cmd)

def init_logging():
    logging.basicConfig(level=logging.DEBUG, filename="gpg.log",
                        filemode="w", format="%(asctime)s %(levelname)-5s %(name)-10s %(threadName)-10s %(message)s")

def print_info(decrypted):
    print('User name: %s' % decrypted.username)
    print('Key id: %s' % decrypted.key_id)
    print('Signature id: %s' % decrypted.signature_id)
    #print('Signature timestamp: %s' % decrypted.sig_timestamp)
    print('Fingerprint: %s' % decrypted.fingerprint)

def main():
    init_logging()
    if os.path.exists('keys'):
        shutil.rmtree('keys')
    gpg = gnupg.GPG(gnupghome='keys')
    key = generate_key(gpg, "Andrew", "Able", "alpha.com",
                            passphrase="andy")
    andrew = key.fingerprint
    key = generate_key(gpg, "Barbara", "Brown", "beta.com")
    barbara = key.fingerprint
    #First - without signing
    data = 'Top secret'
    encrypted = gpg.encrypt_file(StringIO(data), barbara,
                                 #sign=andrew, passphrase='andy',
                                 output='encrypted.txt')
    assert encrypted.status == 'encryption ok'
    # Data is in encrypted.txt. Read it in and verify/decrypt it.
    data = open('encrypted.txt', 'r').read()
    decrypted = gpg.decrypt(data, passphrase='bbrown', output='decrypted.txt')
    print_info(decrypted)
    #Now with signing
    data = 'Top secret'
    encrypted = gpg.encrypt_file(StringIO(data), barbara,
                                 sign=andrew, passphrase='andy',
                                 output='encrypted.txt')
    assert encrypted.status == 'encryption ok'
    # Data is in encrypted.txt. Read it in and verify/decrypt it.
    data = open('encrypted.txt', 'r').read()
    decrypted = gpg.decrypt(data, passphrase='bbrown', output='decrypted.txt')
    print_info(decrypted)

if __name__ == '__main__':
    main()
票数 4
EN
页面原文内容由Stack Overflow提供。腾讯云小微IT领域专用引擎提供翻译支持
原文链接:

https://stackoverflow.com/questions/5673255

复制
相关文章

相似问题

领券
问题归档专栏文章快讯文章归档关键词归档开发者手册归档开发者手册 Section 归档