[openpgp] EdDSA/Ed25519 I-D for OpenPGP

Werner Koch wk at gnupg.org
Thu Aug 21 08:48:44 CEST 2014

On Thu, 21 Aug 2014 02:32, gniibe at fsij.org said:

> I have a question if you plan to submit another I-D for Curve25519 in
> OpenPGP.

I would like to do that but the problem I face is that there is no
suitable specification for the original Curve25519.  Ed25519 is well
defined and the printed and online paper should be sufficient as a
normative reference.

However an I-D for Curve25519 [1] has recently been published.  Thus it
may soon be possible to describe how to use it in OpenPGP.  In
particular on how to use only the X coordinate.

> Do you intend to use this OID of Ed25519 for ECDH, too?

No, that is for Ed25519.

> Or do we use another OID of Curve25519 (the Montgomery curve) for
> ECDH, to specify Curve25519 (ECDH computation)?

For the Montgomery curve Peter Gutman assigned
arlier this year.



[1] http://tools.ietf.org/id/draft-turner-thecurve25519function-01.txt

Die Gedanken sind frei.  Ausnahmen regelt ein Bundesgesetz.

More information about the Gnupg-devel mailing list