ElGamal signature values?
mwy-opgp97 at the-youngs.org
Sat Aug 11 20:15:02 CEST 2001
-----BEGIN PGP SIGNED MESSAGE-----
From: "Jon Callas" <jon at callas.org>
> Can someone who is an implementer answer this? What do I need to do to put
> in the next draft? I'm going to put out another draft in the next couple of
> days -- there's time here at HAL -- and if I can clarify, I will.
I haven't implemented it yet, but I've asked a few times, and for
lack of an answer, I've looked over the GnuPG code.
a=g^k mod p); and,
b=(h-a*x)/k mod (p-1))
where k is random and h is the (padded) message hash.
It seems to apply the same PKCS padding as for RSA signatures.
The two MPIs are encoded in that order (a,b).
The computation matches that found in the Handbook of Applied
Cryptography, among others. I can't comment on whether the PKCS
padding is the usual treatment for ElGamal signatures, though.
-----BEGIN PGP SIGNATURE-----
Version: PGP Personal Privacy 6.5.3
-----END PGP SIGNATURE-----
More information about the Gnupg-devel