ElGamal signature values?

Werner Koch wk at gnupg.org
Mon Aug 13 16:41:01 CEST 2001

On Fri, 10 Aug 2001 09:25:36 -0700, Jon Callas said:

> Can someone who is an implementer answer this? What do I need to do to put
> in the next draft? I'm going to put out another draft in the next couple of

Algorithm Specific Fields for ElGamal signatures:

  - MPI of ElGamal value a = g**k mod p.

  - MPI of ElGamal value b = (h-a*x)/k mod p-1.

The hash h is PKCS-1 padded exactly the same way as for the above
described RSA signatures.

Please add a reference to section 12.5 [ElGamal] and make clear that
the use of ElGamal signatures is not suggested.

> days -- there's time here at HAL -- and if I can clarify, I will.

Hope you had a nice time.


Werner Koch        Omnis enim res, quae dando non deficit, dum habetur
g10 Code GmbH      et non datur, nondum habetur, quomodo habenda est.
Privacy Solutions                                        -- Augustinus

More information about the Gnupg-devel mailing list