yet another tiny feature: deterministic ECDSA

Werner Koch wk at gnupg.org
Fri Apr 12 13:55:21 CEST 2013


On Fri, 12 Apr 2013 09:38, christian at grothoff.org said:

> But not for what we're doing.  If you want to read up on the
> details, see https://gnunet.org/bugs/view.php?id=2564

What is your plan if you have to use a K which leads to either R or S
being 0?  ECDSA loops until it finds a suitable K.  Agreed, this is a
rare event but you better need to have a plan.


Salam-Shalom,

   Werner

-- 
Die Gedanken sind frei.  Ausnahmen regelt ein Bundesgesetz.




More information about the Gcrypt-devel mailing list