On Apr 1, 2014, at 10:48 PM, Paul Hoffman <paul.hoff...@vpnc.org> wrote:
> On Apr 1, 2014, at 7:37 PM, Olafur Gudmundsson <o...@ogud.com> wrote: > >> Why not go to a good ECC instead ? (not sure which one, but not P256 or >> P384) > > Why not P256 or P384? They are the most-studied curves. Some of the newer > curves do have advantages, but they are also newer. > > --Paul Hoffman The verification performance is bad, P256 takes 24x times longer to verify a signature than 2048 bit RSA key. Studied != good performance Olafur _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop