Catch 22 in ECC support of OpenPGP?

Werner Koch wk at
Fri Jan 31 09:44:02 CET 2014

On Fri, 31 Jan 2014 08:50, gniibe at said:

> When Curve25519 will be supported in GnuPG, I think that it's only for
> ECDH (since people use EdDSA with Ed25519, instead of ECDSA with

I think it makes more sense to use an Ed25519 based ECDH in OpenPGP than
to require the implementation of its Montgomery variant Curve25519.
This would benefit small OpenPGP implementation which won't do the
current MUST algorithms but anyway provide compatibility with general
purpose OpenPGP tools.  There might be a small performance drawback but
can be justified by a more compact implementation.  The current ECDH
algo ID can still be used for this if we go without point compression.



Die Gedanken sind frei.  Ausnahmen regelt ein Bundesgesetz.

More information about the Gnupg-devel mailing list