3 ms·
It should be noted that EdDSA is generally implemented in constant time, something that can't be said for RSA. (which different implementations - including Open
by dependenttypes 6y ago
It should be noted that EdDSA is generally implemented in constant time, something that can't be said for RSA. (which different implementations - including OpenSSL which OpenSSH uses - have been found to implement it in a way that allows side channel attacks time and time again)
In addition I am pretty sure that if you compile OpenSSH with support only for EdDSA it does not need to be linked to OpenSSL.
- throw0101a 6y ago> In addition I am pretty sure that if you compile OpenSSH with support only for EdDSA it does not need to be linked to OpenSSL. With the proviso (IIRC) that you will also only have AES-CTR and ChaCha.
- dependenttypes 6y agoI do not know about AES but I do know that it also supports Poly1305 to be used with Chacha20.