I noticed that openssl(1) says that various things have been superseded by 
genpkey, so I tried changing my scripts to use it. It works fine for RSA, but 
the man page is not very helpful on EC. I tried

    openssl genpkey -out key.new -algorithm EC -pkeyopt 
ec_paramgen_curve:secp384r1

and got

    parameter setting error
    139638314907280:error:06089094:digital envelope 
routines:EVP_PKEY_CTX_ctrl:invalid operation:pmeth_lib.c:404:

The curve works with ecparam and also shows up here:

    openssl ecparam -list_curves
      secp112r1 : SECG/WTLS curve over a 112 bit prime field
      secp112r2 : SECG curve over a 112 bit prime field
      secp128r1 : SECG curve over a 128 bit prime field
      secp128r2 : SECG curve over a 128 bit prime field
      secp160k1 : SECG curve over a 160 bit prime field
      secp160r1 : SECG curve over a 160 bit prime field
      secp160r2 : SECG/WTLS curve over a 160 bit prime field
      secp192k1 : SECG curve over a 192 bit prime field
      secp224k1 : SECG curve over a 224 bit prime field
      secp224r1 : NIST/SECG curve over a 224 bit prime field
      secp256k1 : SECG curve over a 256 bit prime field
      secp384r1 : NIST/SECG curve over a 384 bit prime field
      secp521r1 : NIST/SECG curve over a 521 bit prime field
      prime192v1: NIST/X9.62/SECG curve over a 192 bit prime field
      prime192v2: X9.62 curve over a 192 bit prime field
      prime192v3: X9.62 curve over a 192 bit prime field
      prime239v1: X9.62 curve over a 239 bit prime field
      prime239v2: X9.62 curve over a 239 bit prime field
      prime239v3: X9.62 curve over a 239 bit prime field
      prime256v1: X9.62/SECG curve over a 256 bit prime field
      wap-wsg-idm-ecid-wtls6: SECG/WTLS curve over a 112 bit prime field
      wap-wsg-idm-ecid-wtls7: SECG/WTLS curve over a 160 bit prime field
      wap-wsg-idm-ecid-wtls8: WTLS curve over a 112 bit prime field
      wap-wsg-idm-ecid-wtls9: WTLS curve over a 160 bit prime field
      wap-wsg-idm-ecid-wtls12: WTLS curvs over a 224 bit prime field

Any ideas on what I am doing wrong?
_______________________________________________
openssl-users mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users

Reply via email to