Eric Rescorla <[EMAIL PROTECTED]> writes:

> Tom Biggs <[EMAIL PROTECTED]> writes:
> > OK, so I'm not very maths-literate...
> > 
> > I was just wondering what the odds are of a modular exponentiation
> > returning a result of zero in any OpenSSL usage of the modexp.
> Yes, it's technically possible. Consider what happens when
> doing a^b mod p. If a^b happens to equal p or some multiple
> of p then you'll get a zero result. Not likely but it can
> happen.
Now that I think about it, it's not possible in DH precisely
because p is a prime. We know that a and b must be < p
(by definition).

In order for a^b == p then there must be some number 1<x<p such
that ax=p but this is forbidden by p being prime.

I suspect that similar comments apply to RSA.

-Ekr


______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to