RSA signature verification in gpg-agent?

Daniel Kahn Gillmor dkg at fifthhorseman.net
Fri Sep 25 05:41:19 CEST 2015


On Mon 2015-09-21 21:45:09 -0400, NIIBE Yutaka wrote:
> Thus, I think that it might make sense for gpg-agent to verify RSA
> signature generated by smartcard, before returning it to user.

This seems sensible to me.  Given the performance characteristics of RSA
and of hardware smartcards, i can't imagine that this imposes much of a
performance cost either.

Thanks for thinking about this, gniibe.

            --dkg



More information about the Gnupg-devel mailing list