I should also say --

> DSA involves doing some complicated math on a 160-bit value. There's no
> hard requirement the value be generated by SHA-1, and GnuPG/PGP 5+
> provides RIPEMD160 as an alternative, but in reality hardly anyone uses
> RIPEMD160.
> 
> This should not be confused with DSS, the Digital Signature *Standard*,
> which specifies DSA with SHA-1 (and only SHA-1).
(This is the longer answer I alluded to in the preceding message)

DSA has been around for more than thirty years and in those decades has
undergone several rounds of change. The answer I gave there, while
correct, is only correct for *one specific early version* of DSA -- the
version GnuPG and PGP implemented at the time you first created your DSA
certificate.

The final version of DSA that used the conventional discrete logarithm
problem as a basis for security allowed up to 3072-bit keys using
256-bit hashes. However, this has since been declared obsolete by FIPS,
and the latest versions of the standard use DSA defined on an Edwards
curve, I believe.

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

_______________________________________________
Gnupg-users mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-users

Reply via email to