Jelte Jansen <jelte.jan...@sidn.nl> wrote:
>
> We can certainly discuss alternative schemes, RSASSA-PSS is a potential
> alternative, which I understand is considered (much?) better. It has a
> big drawback though, in that it requires salt, which can be a big issue
> for large deployments.

As I understand it the deterministic DSA trick (RFC 6979) also works for
RSA SSA PSS.

Tony.
-- 
f.anthony.n.finch  <d...@dotat.at>  http://dotat.at/  -  I xn--zr8h punycode
South Plymouth, North Biscay: Easterly or northeasterly 4 or 5. Moderate,
occasionally rough at first in north Biscay. Fair. Moderate or good.

_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to