[curves] Certifying EdDSA public keys

Trevor Perrin trevp at trevp.net
Wed Sep 23 09:01:08 PDT 2015

On Wed, Sep 23, 2015 at 12:28 AM, Trevor Perrin <trevp at trevp.net> wrote:
> PureEdDSA would never calculate an R that equals Z.  If you choose the
> Hash carefully to avoid length-extension issues

With some sleep: I don't know why I brought up length-extension, seems
irrelevant (and "choose the Hash" was silly, because the goal was to
be back-compatible with existing signatures made with Ed25519 /

I think what I suggested works in that case.


