[openssl-dev] common factors in (p-1) and (q-1)

Bill Cox waywardgeek at google.com
Sat Aug 1 00:09:12 UTC 2015


On Fri, Jul 31, 2015 at 4:43 PM, Blumenthal, Uri - 0553 - MITLL <
uri at ll.mit.edu> wrote:

> I think adding the recommended check would be beneficial. Considering the
> frequency of ‎key generation, performance impact shouldn't matter all that
> much.
>

Samuel's argument above is one I've heard before from Thomas Porin, which
is why I was not recommending we do or do not do this check.  I was just
estimating the performance hit.

I personally have not gone over the paper Samuel linked to other than to
read the abstract.  However, assuming the paper's claims are correct, which
seems to be backed up by these two fine cryptography experts, I think the
additional check would do more harm than good.

Bill
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mta.openssl.org/pipermail/openssl-dev/attachments/20150731/cce42298/attachment.html>


More information about the openssl-dev mailing list