On Wed, May 30, 2018 at 7:20 AM Andrey Jivsov <cry...@brainhub.org> wrote: > The issue here is that some hardware devices don't implement RSA CRT > method with PSS, because they hard-wide RSA, legacy padding, and CRT > method in one operation. RSA PSS can still be done, but only via a > general modexp operation, which will be ~2x shower. Therefore, in these > scenarios PSS incurs 2x performance penalty.
I'm fairly certain that we've had this discussion before. What is new? _______________________________________________ TLS mailing list TLS@ietf.org https://www.ietf.org/mailman/listinfo/tls