Re: Pure ML-DSA signature verification

"'Alicja Kario' via openssl-users" <[email protected]> Tue, 24 Feb 2026 15:09:03 +0100
Newsgroups gmane.comp.encryption.openssl.user
Organization Red Hat
Message-ID <[email protected]>
On Tuesday, 24 February 2026 14:55:44 CET, Christian Schmidt wrote:
> On 2/24/26 2:42 PM, Viktor Dukhovni wrote:
>> On Tue, Feb 24, 2026 at 02:38:03PM +0100, Christian Schmidt wrote:
>>  ...
>
> You wrote it yourself - openssl is lacking a (simple) API that 
> enables a simple init - update - final verification for 
> algorithms that process the signature early (here: calculate the 
> µ value), and people that just want to work with a cryptographic 
> library need to deep-dive into algorithms.
>
> The lack of such an API, that could be easily generalized with 
> an init_ex function that accepts the signature to be verified, 
> is as such a limitation of openssl.
>
> Regards,
> Christian
>
> PS: If you have an idea how to do the same for ED25519 I'd be 
> highly interested. Having to continuously port patches forward 
> is kind of annoying, and the core ED25519 functions are not 
> exposed enough to be called externally.

The big issue for EdDSA is that for signing, the message needs to be hashed
twice...
-- 
Regards,
Alicja Kario
Principal Quality Engineer, RHEL Crypto team
Web: www.cz.redhat.com
Red Hat Czech s.r.o., Purkyňova 115, 612 00, Brno, Czech Republic

-- 
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/eb7ba430-3676-4439-b7b5-6963e38331bc%40redhat.com.