EdDSA/Ed25519 I-D for OpenPGP

NIIBE Yutaka gniibe at fsij.org
Thu Aug 21 02:32:13 CEST 2014


On 2014-08-19 at 22:04 +0200, Werner Koch wrote:
> I just submitted an I-D for use of Ed25519 in OpenPGP:
> 
>   http://www.ietf.org/id/draft-koch-eddsa-for-openpgp-00.txt

Great.

I have a question if you plan to submit another I-D for Curve25519 in
OpenPGP.

Well, I think that when people say "Curve25519", it refers two
different things: the Montgomery curve itself or the ECDH computation
with the curve.  In the paragraph above, I mean ECDH computation.

Specifically,,, 

> 6.  Curve OID
> 
>    The EdDSA key parameter curve OID is an array of octets that defines
>    a named curve.  The table below specifies the exact sequence of bytes
>    for each named curve referenced in this document:
> 
>    +------------------------+------+------------------------+----------+
>    | OID                    | Len  | Encoding in hex format | Name     |
>    +------------------------+------+------------------------+----------+
>    | 1.3.6.1.4.1.11591.15.1 | 9    | 2B 06 01 04 01 DA 47   | Ed25519  |
>    |                        |      | 0F 01                  |          |
>    +------------------------+------+------------------------+----------+

Do you intend to use this OID of Ed25519 for ECDH, too?

Or do we use another OID of Curve25519 (the Montgomery curve) for
ECDH, to specify Curve25519 (ECDH computation)?
-- 





More information about the Gnupg-devel mailing list