Algorithm Specific Fields for ElGamal signatures:

  - MPI of ElGamal value a = g**k mod p.

  - MPI of ElGamal value b = (h-a*x)/k mod p-1.

The hash h is PKCS-1 padded exactly the same way as for the above
described RSA signatures.

Please add a reference to section 12.5 [ElGamal] and make clear that
the use of ElGamal signatures is not suggested.

