Am Dienstag, 27. Mai 2014, 17:45:48 schrieb Peter Waltenberg: Hi Peter,
>Not quite correct, the prime rands shouldn't come from a DRBG, they >should come from an NRBG (NIST terminology). There's a considerable >difference between the performance of an entropy source and a DRBG. Not sure where you see that, but looking into, say, FIPS 186-4 appendix C.3, it always talks about an "approved RBG". In FIPS 140-2 speak, this implies a DRBG. Can you please give a reference? Ciao Stephan ______________________________________________________________________ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager majord...@openssl.org