3 ms·
RFC6637: Elliptic Curve Cryptography in OpenPGP (2012)
- CiPHPerCoder 10y agoThis is all NIST Curve ECC (P-256, P-384, etc.) and should be discouraged in favor of the curves in RFC 7748.
- jfindley 10y agoWhile I 100% agree, it should be noted that this particular RFC predates the Ed25519 RFC by some years. OpenPGP appears (to me, as an outsider) to move at an extremely glacial pace - I hope that they'll get there in time. EDIT: I don't mean it predates the design of Ed25519, but it seems unlikely that the writers of this RFC would base their proposal on something not formalized in another RFC.
- CiPHPerCoder 10y ago> While I 100% agree, it should be noted that this particular RFC predates the Ed25519 RFC by some years. Sure, I'm not saying this RFC is misguided, just outdated and people should use Curve25519 or Curve448 for their ECDH/EdDSA needs (and stop using foot-bullety ECDSA).
- Sami_Lehtinen 10y agoOpenPGP does support Curve 25519.
- CiPHPerCoder 10y agoYes, but this RFC does not.
- lvh 10y agoDo you mean GPG? My understanding is that there's no OpenPGP standard for Curve25519; and it's an optional-off-by-default build time flag for GPG. (The GPGTools binary does not support Curve25519.)
- wslh 10y agoBTW, my company added support for ECC in OpenPGP.js: https://github.com/Jaxx-io/openpgpjs-secp256k1 https://github.com/Jaxx-io/openpgpjs-secp256k1 this implementation also includes the elliptic curves for the RFC6637. More information here: https://github.com/Jaxx-io/openpgpjs-secp256k1/blob/master/README_secp256k1.md https://github.com/Jaxx-io/openpgpjs-secp256k1/blob/master/R...