PLValidateEd25519Identity

Cryptography, digital signatures

Description

Checks that an Ed25519 private key belongs to a certificate and extracts the 32-byte signing seed

The certificate must carry an Ed25519 public key and the private key must be the PKCS#8 form whose embedded secret matches that public key

Syntax

Delphi

Function PLValidateEd25519Identity(Const CertificateDER, PrivateKeyDER: AnsiString;
  Out Seed: AnsiString): Boolean;

Parameters

CertificateDERDER-encoded certificate holding the Ed25519 public key
PrivateKeyDERDER-encoded PKCS#8 private key
SeedReceives the 32-byte seed derived from the public-key scalar half; empty on failure

Return values

FalseThe pair does not match, is not Ed25519, or the encodings are malformed
TrueSeed holds 32 bytes usable with Ed25519Sign

Remarks

This is the identity gate behind SetSignProcessEd25519Identity; passing validation means the signing process can derive the same signature as the certificate owner without CNG

See also

SetSignProcessEd25519Identity, Ed25519Sign, Ed25519PublicKeyFromSeed, PLBuildModernDetachedCMS