[Bug 1081723] mozilla-nss package does not build reproducibly from shlibsign
6 Mar
2018
6 Mar
'18
16:11
http://bugzilla.suse.com/show_bug.cgi?id=1081723 http://bugzilla.suse.com/show_bug.cgi?id=1081723#c4 --- Comment #4 from Bernhard Wiedemann <bwiedemann@suse.com> --- I guess, it is about this:
Generate a random per-message value k where 1 < k < q
With DSA, the entropy, secrecy, and uniqueness of the random signature value k are critical.
Implementing https://tools.ietf.org/html/rfc6979 should help to make results reproducible and make the signature even safer. We should probably involve upstream in that. Who does that? -- You are receiving this mail because: You are on the CC list for the bug.
2443
Age (days ago)
2443
Last active (days ago)
0 comments
1 participants
participants (1)
-
bugzilla_noreply@novell.com