On Apr 1, 2014, at 10:48 PM, Paul Hoffman <[email protected]> wrote:
> On Apr 1, 2014, at 7:37 PM, Olafur Gudmundsson <[email protected]> wrote: > >> Why not go to a good ECC instead ? (not sure which one, but not P256 or >> P384) > > Why not P256 or P384? They are the most-studied curves. Some of the newer > curves do have advantages, but they are also newer. > > --Paul Hoffman The verification performance is bad, P256 takes 24x times longer to verify a signature than 2048 bit RSA key. Studied != good performance Olafur _______________________________________________ DNSOP mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsop
