{"templateId":"markdown","versions":[{"version":"v1.39","label":"v1.39 STS","link":"/products/custody/v1.39/resources/openssl-examples","default":true,"active":false,"folderId":"c15a2701"},{"version":"v1.38","label":"v1.38 STS","link":"/products/custody/v1.38/resources/openssl-examples","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.34","label":"v1.34 LTS","link":"/products/custody/v1.34/resources/openssl-examples","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.26","label":"v1.26 LTS","link":"/products/custody/v1.26/resources/openssl-examples","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.19","label":"v1.19 LTS","link":"/products/custody/v1.19/resources/openssl-examples","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.15","label":"v1.15 LTS","link":"/products/custody/v1.15/resources/openssl-examples","default":false,"active":true,"folderId":"c15a2701"}],"sharedDataIds":{"sidebar":"sidebar-products/custody/@v1.15/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["admonition","tabs","tab"]},"type":"markdown"},"seo":{"title":"OpenSSL examples","description":"User guides, API reference, and support resources.","siteUrl":"https://docs.ripple.com","lang":"en-US","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"openssl-examples","__idx":0},"children":["OpenSSL examples"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["These Open SSL examples can be used for key generation and signature in non-production environments."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["OpenSSL is not suitable for production environments. You always need to generate and store production keys using a cryptographically secure method (a key management system)."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"key-generation-examples","__idx":1},"children":["Key generation examples"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following examples show how to generate a key pair using the common OpenSSL toolbox."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"key-generation-using-secp256r1-elliptic-curve","__idx":2},"children":["Key generation using secp256r1 elliptic curve"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To generate a key pair using the secp256r1 elliptic curve, enter the following commands:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"secp256r1 private key","header":{"title":"secp256r1 private key","controls":{"copy":{}}},"source":"openssl ecparam -genkey -name secp256r1 -noout -out privateKey.pem\n","lang":"sh"},"children":[]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"secp256r1 public key","header":{"title":"secp256r1 public key","controls":{"copy":{}}},"source":"openssl ec -in privateKey.pem -pubout -outform DER | openssl base64 -A -out publicKey.pem\n","lang":"sh"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"key-generation-using-secp256k1-elliptic-curve","__idx":3},"children":["Key generation using secp256k1 elliptic curve"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To generate a key pair using the secp256k1 elliptic curve, enter the following commands:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"secp256k1 private key","header":{"title":"secp256k1 private key","controls":{"copy":{}}},"source":"openssl ecparam -genkey -name secp256k1 -noout -out privateKey.pem\n","lang":"sh"},"children":[]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"secp256k1 public key","header":{"title":"secp256k1 public key","controls":{"copy":{}}},"source":"openssl ec -in privateKey.pem -pubout -outform DER | openssl base64 -A -out publicKey.pem\n","lang":"sh"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"key-generation-using-ed25519-elliptic-curve","__idx":4},"children":["Key generation using ED25519 elliptic curve"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To generate a key pair using the ED25519 elliptic curve, enter the following commands:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"ED25519 private key","header":{"title":"ED25519 private key","controls":{"copy":{}}},"source":"openssl genpkey -algorithm Ed25519 -out privateKey.pem\n","lang":"sh"},"children":[]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"ED25519 public key","header":{"title":"ED25519 public key","controls":{"copy":{}}},"source":"openssl ec -in privateKey.pem -pubout -outform DER | openssl base64 -A -out publicKey.pem\n","lang":"sh"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"view-the-output","__idx":5},"children":["View the output"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the previous examples, the public key is exported without the header and footer, which is the format that ","Ripple Custody"," expects."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To view the contents of the key files:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To view the contents of the private key files, for each file, enter the following command:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"View private key","header":{"title":"View private key","controls":{"copy":{}}},"source":"cat privateKey.pem\n","lang":"sh"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The output is similar to the following example:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"Private key output","header":{"title":"Private key output","controls":{"copy":{}}},"source":"-----BEGIN EC PRIVATE KEY-----\nMHcCAQEEIEfoycax3w8+JvkNv+L0CHmNUAHUcgCxlnOIpw/CoXzxoAoGCCqGSM49\nAwEHoUQDQgAEg36xU2KQ6xLPCvZ3JXZYf5pFCagAb7WGMlYCN92zzgi737EOkDOC\nMlZB0TY8CbzRHhG4RUdKuLkdRtD+OVIu2w==\n-----END EC PRIVATE KEY-----\n","lang":"sh"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To view the contents of the public key files, for each file, enter the following command:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"View public key","header":{"title":"View public key","controls":{"copy":{}}},"source":"cat publicKey.pem\n","lang":"sh"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The output is similar to the following example:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"Public key output","header":{"title":"Public key output","controls":{"copy":{}}},"source":"MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEg36xU2KQ6xLPCvZ3JXZYf5pFCagAb7WGMlYCN92zzgi737EOkDOCMlZB0TY8CbzRHhG4RUdKuLkdRtD+OVIu2w==\n","lang":"sh"},"children":[]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"signature-examples","__idx":6},"children":["Signature examples"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following examples show how to:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Sign a challenge to obtain a JSON web token (JWT)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Submit an intent"]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"sign-a-challenge-to-obtain-a-jwt","__idx":7},"children":["Sign a challenge to obtain a JWT"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This example shows how to sign a challenge. These steps generate the output that you need to obtain a JWT for authentication in ","Ripple Custody","."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For more information about JWT generation, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/v1.15/api/get-started/jwt"},"children":["Obtain a JSON web token (JWT)"]}," in the API guide."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To generate the signature:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Prepare a random string to use as a challenge, for example a UUID, in a text file called ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["challenge.txt"]},":"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"Prepare the challenge string","header":{"title":"Prepare the challenge string","controls":{"copy":{}}},"source":"user@HOSTNAME:~/test$ cat challenge.txt\n22ff6b83-784c-46ab-8514-096c3c2b93ff\n","lang":"sh"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Sign the challenge with the secp256r1, secp256k1, or ED25519 elliptic curve."]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To sign the challenge with secp256r1 or secp256k1, enter the following command:"]},{"$$mdtype":"Tag","name":"Tabs","attributes":{"size":"medium"},"children":[{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"MacOS","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"Signature with secp256r1 or secp256k1","header":{"title":"Signature with secp256r1 or secp256k1","controls":{"copy":{}}},"source":"openssl dgst -sha256 -sign privateKey.pem challenge.txt | base64\n","lang":"sh"},"children":[]}]},{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"Linux","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"Signature with secp256r1 or secp256k1","header":{"title":"Signature with secp256r1 or secp256k1","controls":{"copy":{}}},"source":"openssl dgst -sha256 -sign privateKey.pem challenge.txt | base64 -w0\n","lang":"sh"},"children":[]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The output of the signature operation is in raw format, which we converted to Base64, to give an output similar to the following example:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"Output of secp256r1 or secp256k1","header":{"title":"Output of secp256r1 or secp256k1","controls":{"copy":{}}},"source":"MEQCIGtDBRAdRgUn9kT3olUGBmQbzEwQ2wQr8Ucevu6uwDmXAiB+OISmprOU7TwI0XUnyNuNQpBpyze9fnaLTp5LxZuJ/Q==\n","lang":"sh"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To sign the challenge with ED25519:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Enter the following command:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"Signature with ED25519","header":{"title":"Signature with ED25519","controls":{"copy":{}}},"source":"openssl pkeyutl -sign -inkey privateKey.pem  -rawin -in challenge.txt -out sig.dat\n","lang":"sh"},"children":[]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Because the signature output of ED25519 is in compact format, we must first convert it to DER format."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Convert the compact signature to DER format, and then encode it in Base64, with the one of the following commands:"]},{"$$mdtype":"Tag","name":"Tabs","attributes":{"size":"medium"},"children":[{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"Linux","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"Signature conversion to DER and Base64","header":{"title":"Signature conversion to DER and Base64","controls":{"copy":{}}},"source":"cat sig.dat | hexdump -v -e '/1 \"%02x\"' | sed 's/\\(.\\{64\\}\\)\\(.\\{64\\}\\)/30440220\\10220\\2/g' | xxd -r -p | base64 -w0\n","lang":"sh"},"children":[]}]},{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"MacOS","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"Signature conversion to DER and Base64","header":{"title":"Signature conversion to DER and Base64","controls":{"copy":{}}},"source":"cat sig.dat | hexdump -v -e '/1 \"%02x\"' | sed 's/\\(.\\{64\\}\\)\\(.\\{64\\}\\)/30440220\\10220\\2/g' | xxd -r -p | base64 -b0\n","lang":"sh"},"children":[]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The output is similar to the following example:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"Output of ED25519 after conversion","header":{"title":"Output of ED25519 after conversion","controls":{"copy":{}}},"source":"MEQCICVs3TeU6DsaKc/DC3Y4VerQjiy/Sm4Prfyoh4yFKj1TAiBPu6/c5rxNxCU5Gl2NZH+orCUHKGFTAxcrDxRQqTYSBA==\n","lang":"sh"},"children":[]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"success"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You can submit this output to ","Ripple Custody"," to obtain a JWT. For more information, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/v1.15/api/get-started/jwt#obtain-a-token"},"children":["Obtain a token"]},"."]}]}]}]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"sign-a-payload-for-intent-submission","__idx":8},"children":["Sign a payload for intent submission"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This example shows how to sign a payload before you submit an intent to create or update system data. For more information, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/v1.15/api/get-started/key-operations/update/intent-signature"},"children":["Sign intents"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To sign a payload for intent submission:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Save the following example in a JSON file named ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_CreateAccount.json"]},":"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"json","data-title":"Example account creation intent in JSON format","header":{"title":"Example account creation intent in JSON format","controls":{"copy":{}}},"source":"{\n    \"author\":{  \n        \"id\":\"e02f08ce-e515-46fa-9ed3-326179a1de89\",\n        \"domainId\":\"789265d6-aea6-4c7b-9d68-1a532ea3060b\"\n    },\n    \"expiryAt\":\"2024-08-24T14:15:22Z\",\n    \"targetDomainId\":\"789265d6-aea6-4c7b-9d68-1a532ea3060b\",\n    \"id\":\"1b96fd0f-4e50-4782-9fae-ff0fce7f982c\",\n    \"payload\":{\n        \"id\":\"9dbc612f-b98a-4c83-8143-9d33e1865127\",\n        \"alias\":\"OpenSSL Test Account 1\",\n        \"providerDetails\":{\n            \"vaultId\":\"00000000-0000-0000-0000-000000000000\",\n            \"keyStrategy\":\"VaultHard\",\n            \"type\":\"Vault\"\n        },\n        \"ledgerIds\":[\"bitcoin-cash-testnet\"],\n        \"lock\":\"Unlocked\",\n        \"customProperties\":{},\n        \"type\":\"v0_CreateAccount\"\n    },\n    \"description\":\"OpenSSL Creation of Test Account 1\",\n    \"customProperties\":{},\n    \"type\":\"Propose\"\n}\n","lang":"json"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Sort the JSON payload, with the following command:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"Sort the payload file","header":{"title":"Sort the payload file","controls":{"copy":{}}},"source":"cat v0_CreateAccount.json | jq -j -S -c > v0_CreateAccount_Sorted.json\n","lang":"sh"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following example shows the output of the sorted JSON file:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"json","data-title":"Sorted payload output","header":{"title":"Sorted payload output","controls":{"copy":{}}},"source":"{\"author\":{\"domainId\":\"777265d6-aea6-4c7b-9d68-1a532ea3060b\",\"id\":\"e02f08ce-e515-46fa-9ed3-326179a1de77\"},\"customProperties\":{},\"description\":\"OpenSSL Creation of Test Account 1\",\"expiryAt\":\"2024-08-24T14:15:22Z\",\"id\":\"1b95fd0f-4e50-4782-9fae-ff0fce7f982c\",\"payload\":{\"alias\":\"OpenSSL Test Account 2\",\"customProperties\":{},\"id\":\"9cbc612f-b98a-4c83-8143-9d33e1865127\",\"ledgerIds\":[\"bitcoin-cash-testnet\"],\"lock\":\"Unlocked\",\"providerDetails\":{\"keyStrategy\":\"VaultHard\",\"type\":\"Vault\",\"vaultId\":\"00000000-0000-0000-0000-000000000000\"},\"type\":\"v0_CreateAccount\"},\"targetDomainId\":\"777265d6-aea6-4c7b-9d68-1a532ea3060b\",\"type\":\"Propose\"}\n","lang":"json"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Sign the payload using secp256r1, secp256k1, or ED25519."]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["To sign using secp256r1 or secp256k1, enter one of the following commands:"]}]},{"$$mdtype":"Tag","name":"Tabs","attributes":{"size":"medium"},"children":[{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"Linux","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"Payload signature using secp256r1 or secp256k1","header":{"title":"Payload signature using secp256r1 or secp256k1","controls":{"copy":{}}},"source":"openssl dgst -sha256 -sign privateKey.pem v0_CreateAccount_Sorted.json | base64 -w0\n","lang":"sh"},"children":[]}]},{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"MacOS","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"Payload signature using secp256r1 and secp256k1","header":{"title":"Payload signature using secp256r1 and secp256k1","controls":{"copy":{}}},"source":"openssl dgst -sha256 -sign privateKey.pem v0_CreateAccount_Sorted.json | base64 -b0\n","lang":"sh"},"children":[]}]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["To sign using ED25519, enter one of the following commands:"]}]},{"$$mdtype":"Tag","name":"Tabs","attributes":{"size":"medium"},"children":[{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"Linux","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"Payload signature using ED25519","header":{"title":"Payload signature using ED25519","controls":{"copy":{}}},"source":"tmp=$(mktemp)\ncat v0_CreateAccount_Sorted.json | sha256sum | xxd -r -p > ${tmp}\nopenssl pkeyutl -sign -inkey privateKey.pem -rawin -in ${tmp} | hexdump -v -e '/1 \"%02x\"' | sed 's/\\(.\\{64\\}\\)\\(.\\{64\\}\\)/30440220\\10220\\2/g' | xxd -r -p | base64 -w0\nrm -f ${tmp}\n","lang":"sh"},"children":[]}]},{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"MacOS","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"Payload signature using ED25519","header":{"title":"Payload signature using ED25519","controls":{"copy":{}}},"source":"tmp=$(mktemp)\ncat v0_CreateAccount_Sorted.json | sha256sum | xxd -r -p > ${tmp}\nopenssl pkeyutl -sign -inkey privateKey.pem -rawin -in ${tmp} | hexdump -v -e '/1 \"%02x\"' | sed 's/\\(.\\{64\\}\\)\\(.\\{64\\}\\)/30440220\\10220\\2/g' | xxd -r -p | base64 -b0\nrm -f ${tmp}\n","lang":"sh"},"children":[]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"check-the-signature-returned-by-ripple-custody","__idx":9},"children":["Check the signature returned by Ripple Custody"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["All data payloads that you retrieve from ","Ripple Custody"," that are part of the secure data include a signature. To verify the authenticity of this signature, we highly recommend that you run a verification step."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To check the signature:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Retrieve the public key of ","Ripple Custody",", with the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/v1.15/api/reference/openapi/systemproperties/getsystemproperties"},"children":["List system properties"]}," API operation."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The API operation returns the public key as part of the response:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"json","data-title":"Custody public key","header":{"title":"Custody public key","controls":{"copy":{}}},"source":"{\n    \"id\": \"CUSTODY_API_KEY\",\n    \"value\": {\n        \"publicKey\": {\n            \"value\": \"MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE1WXjDbBcWEVmqObzEndfnug+nd4EOEqcXMY5a5I0XvfRq1+K6Z9K1DdZ2YgFIbuzdX2Z2kOfE/fcDj/QzF5IAw==\",\n            \"type\": \"PublicKey\"\n        }\n    }\n}\n","lang":"json"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Save the public key value into a text file, together with a header and footer, in the following format:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"Formatted public key file","header":{"title":"Formatted public key file","controls":{"copy":{}}},"source":"CustodypublicKey.pem\n-----BEGIN PUBLIC KEY-----\nMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE1WXjDbBcWEVmqObzEndfnug+nd4EOEqcXMY5a5I0XvfRq1+K6Z9K1DdZ2YgFIbuzdX2Z2kOfE/fcDj/zF5IAw==\n-----END PUBLIC KEY-----\n","lang":"sh"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Prepare the signature string. OpenSSL expects the signature in raw format, so the signature string received needs to be converted using the following command:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"Signature conversion to raw format","header":{"title":"Signature conversion to raw format","controls":{"copy":{}}},"source":"openssl enc -d -A -base64 -in signatureByHarmonize.txt -out signatureByHarmonize.bin\n","lang":"sh"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Sort the result, using a command similar to step 2 of ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#sign-a-payload-for-intent-submission"},"children":["Sign a payload for intent submission"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Once you have the sorted object, the ","Ripple Custody"," public key, and the signature in binary format, to verify the data, run the following command:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","data-title":"Data verification","header":{"title":"Data verification","controls":{"copy":{}}},"source":"openssl pkeyutl -verify -pubin -inkey CustodypublicKey.pem -rawin -in Sorted_Object.json -sigfile signatureByHarmonize.bin\n","lang":"sh"},"children":[]}]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"success"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If the signature is valid, ","Ripple Custody"," returns the following message: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Signature Verified Successfully"]}]}]}]},"headings":[{"value":"OpenSSL examples","id":"openssl-examples","depth":1},{"value":"Key generation examples","id":"key-generation-examples","depth":2},{"value":"Key generation using secp256r1 elliptic curve","id":"key-generation-using-secp256r1-elliptic-curve","depth":3},{"value":"Key generation using secp256k1 elliptic curve","id":"key-generation-using-secp256k1-elliptic-curve","depth":3},{"value":"Key generation using ED25519 elliptic curve","id":"key-generation-using-ed25519-elliptic-curve","depth":3},{"value":"View the output","id":"view-the-output","depth":3},{"value":"Signature examples","id":"signature-examples","depth":2},{"value":"Sign a challenge to obtain a JWT","id":"sign-a-challenge-to-obtain-a-jwt","depth":3},{"value":"Sign a payload for intent submission","id":"sign-a-payload-for-intent-submission","depth":3},{"value":"Check the signature returned by Ripple Custody","id":"check-the-signature-returned-by-ripple-custody","depth":3}],"frontmatter":{"seo":{"title":"OpenSSL examples"}},"lastModified":"2025-10-28T02:35:57.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/custody/v1.15/resources/openssl-examples","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}