yet another tiny feature: deterministic ECDSA

Werner Koch wk at
Fri Apr 12 13:55:21 CEST 2013

On Fri, 12 Apr 2013 09:38, christian at said:

> But not for what we're doing.  If you want to read up on the
> details, see

What is your plan if you have to use a K which leads to either R or S
being 0?  ECDSA loops until it finds a suitable K.  Agreed, this is a
rare event but you better need to have a plan.



Die Gedanken sind frei.  Ausnahmen regelt ein Bundesgesetz.

More information about the Gcrypt-devel mailing list