Re: Pure ML-DSA signature verification
Viktor Dukhovni <[email protected]> Wed, 25 Feb 2026 00:42:55 +1100
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <[email protected]> |
On Tue, Feb 24, 2026 at 02:38:03PM +0100, Christian Schmidt wrote:
> Looking at page 27 of FIPS 204 to me implies that in ML-DSA the signature
> that is to be verified also is processed before the actual message data,
> though I did not actually try to understand the algorithm in detail. So
> ML-DSA would also need an init_ex function that can receive the signature
> early.
>
> As such, I'd say it's a limitation of openssl for ML-DSA, too.
Or you could just not make up the answer out of thin air. :-)
--
Viktor. 🇺🇦 Слава Україні!
--
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/aZ2q31t8gOE6XuKM%40chardros.imrryr.org.