0Pricing
Cryptology Academy · Lesson

RSA Signatures: Sign & Verify

Step through the math of signing a document hash with a private key.

RSA Signatures: Sign & Verify is a free Cryptology Academy lesson on CoddyKit — lesson 2 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Cryptology Academy learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.

Welcome

RSA signatures flip the key roles: the private key signs and the public key verifies. This enables anyone to verify your identity using your public key.

RSA Signing Math

To sign message M with private key (d, n): 1. H = SHA256(M) 2. sig = H^d mod n The signature is a number with the same bit length as n.

RSA Verification Math

To verify signature sig with public key (e, n): 1. H' = sig^e mod n 2. H = SHA256(M) 3. Valid if H == H' Anyone with the public key can verify — no secret needed.

PKCS#1 v1.5 Signature Padding

Raw RSA signatures are malleable. PKCS#1 v1.5 pads the hash before signing: 0x00 0x01 [0xFF padding] 0x00 [DigestInfo] [Hash] Verification checks the exact padding structure.

RSA-PSS: Better Padding

RSA-PSS (Probabilistic Signature Scheme) uses random salt, making each signature different even for the same message. Provably secure in the random oracle model. Preferred over PKCS#1 v1.5.

Python RSA Signing (PSS)

from cryptography.hazmat.primitives.asymmetric import padding from cryptography.hazmat.primitives import hashes signature = private_key.sign( message, padding.PSS( mgf=padding.MGF1(hashes.SHA256()), salt_length=padding.PSS.MAX_LENGTH ), hashes.SHA256() )

Python RSA Verification

try: public_key.verify( signature, message, padding.PSS( mgf=padding.MGF1(hashes.SHA256()), salt_length=padding.PSS.MAX_LENGTH ), hashes.SHA256() ) print('Valid!') except InvalidSignature: print('Invalid!')

Signature Length

RSA-2048 signature: 256 bytes. RSA-4096: 512 bytes. ECDSA-256 signature: ~71 bytes (variable DER encoding). The signature contains the full modular exponentiation output.

Blind Signatures

A blind signature allows the signer to sign a message without seeing its content. Used in e-voting and e-cash: the bank signs a blinded token, user unblinds it — untraceable cash.

RSA Signature in Certificate Chain

Let's Encrypt signs your server certificate with its intermediate CA's RSA private key. Your server's public key is in the certificate body. TLS clients verify this chain automatically.

Certificate Transparency

Certificate Transparency logs all issued certificates in a cryptographically-verifiable Merkle tree. Signed Certificate Timestamps (SCTs) prove inclusion in the log before issuance.

Quick Check

In RSA signature verification, which key is used to verify the signature?

Recap

RSA signatures are secure with proper padding. Next we compare RSA with DSA and ECDSA signature schemes.

Frequently asked questions

Is the “RSA Signatures: Sign & Verify” lesson free?

Yes — the full text of “RSA Signatures: Sign & Verify” is free to read here on the web, and the Cryptology Academy course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Cryptology Academy course, upgrade to CoddyKit PRO.

What will I learn in “RSA Signatures: Sign & Verify”?

Step through the math of signing a document hash with a private key. You practise Cryptology Academy with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.

Do I need any experience to start Cryptology Academy?

No prior experience is required. Cryptology Academy on CoddyKit is structured for beginners through advanced learners; this is — lesson 2 of 4, so you can start here or from the beginning and move at your own pace.

How long does the “RSA Signatures: Sign & Verify” lesson take?

Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.

Can I write and run code in this Cryptology Academy lesson?

Yes. Every Cryptology Academy lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.

All lessons in this course

  1. What Is a Digital Signature?
  2. RSA Signatures: Sign & Verify
  3. DSA & ECDSA Signature Schemes
  4. Signatures in the Wild: Code Signing & Email
← Back to Cryptology Academy