Am Dienstag, 27. Mai 2014, 17:45:48 schrieb Peter Waltenberg:

Hi Peter,

>Not quite correct, the prime rands shouldn't come from a DRBG, they
>should come from an NRBG (NIST terminology). There's a considerable
>difference between the performance of an entropy source and a DRBG.

Not sure where you see that, but looking into, say, FIPS 186-4 appendix 
C.3, it always talks about an "approved RBG". In FIPS 140-2 speak, this 
implies a DRBG.

Can you please give a reference?

Ciao
Stephan
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [email protected]
Automated List Manager                           [email protected]

Reply via email to