Eric Rescorla <[EMAIL PROTECTED]> writes:
> Tom Biggs <[EMAIL PROTECTED]> writes:
> > OK, so I'm not very maths-literate...
> >
> > I was just wondering what the odds are of a modular exponentiation
> > returning a result of zero in any OpenSSL usage of the modexp.
> Yes, it's technically possible. Consider what happens when
> doing a^b mod p. If a^b happens to equal p or some multiple
> of p then you'll get a zero result. Not likely but it can
> happen.
Now that I think about it, it's not possible in DH precisely
because p is a prime. We know that a and b must be < p
(by definition).
In order for a^b == p then there must be some number 1<x<p such
that ax=p but this is forbidden by p being prime.
I suspect that similar comments apply to RSA.
-Ekr
______________________________________________________________________
OpenSSL Project http://www.openssl.org
User Support Mailing List [EMAIL PROTECTED]
Automated List Manager [EMAIL PROTECTED]