cv25519 scalar byte order

Werner Koch wk at
Mon Feb 19 15:23:10 CET 2018

On Wed, 14 Feb 2018 06:13, gniibe at said:

> I wonder if we have difference in the interpretation of secret part
> (skey[3]).
> In GnuPG, this part is interpreted as standard MPI representation
> (big-endian).
> For better interoperability, we could support the prefix 0x40 for this
> secret part, I suppose.

That would be incorrect.  The prefix (e.g. 0x40) indicates a _point_
format and not the format of a scalar.  Thus skey[3] MAY not have this



#  Please read:  Daniel Ellsberg - The Doomsday Machine  #
Die Gedanken sind frei.  Ausnahmen regelt ein Bundesgesetz.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 227 bytes
Desc: not available
URL: <>

More information about the Gnupg-devel mailing list