On 27/07/2026 19:56, Robert J. Hansen via Gnupg-users wrote:
Elgamal signatures were added because ... I am unaware of the case for
including these. It was widely regarded as a mistake.
Patent claims and fear of NSA-designed algorithms, that was the drive
for Elgamal signatures, now I remember. Sorry for the oversight.
Also, El Gamal's DH-based signature algorithm was an independently
designed predecessor of DSA,specifically because: 1. The DSA
simplification to reduce some fields to the hash size (notnecessarily
160 bits!) was a later optimization of ElGamal by NSA. 2. The RSA
security conjecture had not yet accumulated enough evidence to be
trusted, specifically there was no hard evidencethat breaking an RSA
key was as NP-hard as the discrete logarithm problem.
And Ukrainian. DSTU-7456.
DSTU-7564, sorry. Commonly called Kupyna/Купина outside of government
service, I think.
For long term security, having at least two sets of up to date algorithms
is considered good practice because attacks always get stronger, never
weaker (except of cause the cost of hardware, which is now increasing).
Enjoy
Jakob
--
Jakob Bohm, CIO, Partner, WiseMo A/S. https://www.wisemo.com
Transformervej 29, 2860 Søborg, Denmark. Direct +45 31 13 16 10
This public discussion message is non-binding and may contain errors.
WiseMo - Remote Service Management for PCs, Phones and Embedded
_______________________________________________
Gnupg-users mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-users