[curves] Certifying EdDSA public keys

Trevor Perrin trevp at trevp.net
Wed Sep 23 09:01:08 PDT 2015


On Wed, Sep 23, 2015 at 12:28 AM, Trevor Perrin <trevp at trevp.net> wrote:
>
> PureEdDSA would never calculate an R that equals Z.  If you choose the
> Hash carefully to avoid length-extension issues

With some sleep: I don't know why I brought up length-extension, seems
irrelevant (and "choose the Hash" was silly, because the goal was to
be back-compatible with existing signatures made with Ed25519 /
SHA512.)

I think what I suggested works in that case.

Trevor


More information about the Curves mailing list