Am Dienstag, 27. Mai 2014, 17:45:48 schrieb Peter Waltenberg:

Hi Peter,

>Not quite correct, the prime rands shouldn't come from a DRBG, they
>should come from an NRBG (NIST terminology). There's a considerable
>difference between the performance of an entropy source and a DRBG.

Not sure where you see that, but looking into, say, FIPS 186-4 appendix 
C.3, it always talks about an "approved RBG". In FIPS 140-2 speak, this 
implies a DRBG.

Can you please give a reference?

Ciao
Stephan
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       openssl-dev@openssl.org
Automated List Manager                           majord...@openssl.org

Reply via email to