# Verification by a principal fails with an error 2

**URL:** <https://forum.dfinity.org/t/verification-by-a-principal-fails-with-an-error-2/27156>\
**Category:** Developers\
**Created:** [January 31, 2024, 8:39am UTC](https://forum.dfinity.org/t/verification-by-a-principal-fails-with-an-error-2/27156 "2024-01-31T08:39:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![qwertytrewq](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/qwertytrewq/32/10423_2.png) [@qwertytrewq](https://forum.dfinity.org/u/qwertytrewq)\
**Post date:** [January 31, 2024, 8:39am UTC](https://forum.dfinity.org/t/verification-by-a-principal-fails-with-an-error-2/27156/1 "2024-01-31T08:39:56Z")

</div>

(I deleted my previous email on this topic, because I had a wrong hex encoding, but after fixing that, the bug described in this email nevertheless persists.)

In Python `key = ecdsa.VerifyingKey.from_string(public_key, curve=ecdsa.SECP256k1, hashfunc=hashlib.sha256)`,  
where `public_key` is the binary encoding of a principal, produces  
`ecdsa.errors.MalformedPointError: Length of string does not match lengths of any of the enabled (hybrid, raw, compressed, uncompressed) encodings of the curve.`

The length of `public_key` in my test is 29 bytes.

Please help me to understand, how to verify the message.

---

<div class="post-metadata">

**Author:** ![qwertytrewq](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/qwertytrewq/32/10423_2.png) [@qwertytrewq](https://forum.dfinity.org/u/qwertytrewq)\
**Post date:** [January 31, 2024, 9:36am UTC](https://forum.dfinity.org/t/verification-by-a-principal-fails-with-an-error-2/27156/2 "2024-01-31T09:36:44Z")

</div>

If I retrieve public key by:

```typescript
const pubkey = authClient.getIdentity().getPublicKey();

```

and then use `pubkey.toDer()` (in TypeScript) to extract the key, the length of the key (62) still does not match the requirements of `ecdsa.VerifyingKey.from_string` in Python.

---

<div class="post-metadata">

**Author:** ![andrea](https://avatars.discourse-cdn.com/v4/letter/a/c37758/32.png) [@andrea](https://forum.dfinity.org/u/andrea)\
**Post date:** [January 31, 2024, 11:46am UTC](https://forum.dfinity.org/t/verification-by-a-principal-fails-with-an-error-2/27156/3 "2024-01-31T11:46:04Z")

</div>

> [@qwertytrewq](#):
>
> ```auto
> const pubkey = authClient.getIdentity().getPublicKey();
> 
> ```

Is this from the agent? Can you try `toRaw` or `rawKey` instead of `toDer()`? According to the error message you received it seems that raw representation may be supported in the python code you are attempting to use.

> The length of `public_key` in my test is 29 bytes.

This is definitely too short, that is probably a (self-authenticating) principal, not a public key. Public keys should be at least 33 bytes for ECDSA keys.

---

<div class="post-metadata">

**Author:** ![qwertytrewq](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/qwertytrewq/32/10423_2.png) [@qwertytrewq](https://forum.dfinity.org/u/qwertytrewq)\
**Post date:** [January 31, 2024, 1:54pm UTC](https://forum.dfinity.org/t/verification-by-a-principal-fails-with-an-error-2/27156/4 "2024-01-31T13:54:02Z")

</div>

Yes, it’s from the agent.

`console.log("EEE", [authClient.getIdentity().getPublicKey().toRaw, authClient.getIdentity().getPublicKey().rawKey]);`  
outputs  
`EEE [undefined, undefined]`

---

<div class="post-metadata">

**Author:** ![qwertytrewq](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/qwertytrewq/32/10423_2.png) [@qwertytrewq](https://forum.dfinity.org/u/qwertytrewq)\
**Post date:** [January 31, 2024, 3:52pm UTC](https://forum.dfinity.org/t/verification-by-a-principal-fails-with-an-error-2/27156/5 "2024-01-31T15:52:45Z")

</div>

Another solution would be converting from DER to `raw` public key format in Python. I also don’t know how.
