Replies: 2 comments
-
I think we'd want to provide this as it seems generally useful for testing, as you can do test vectors etc instead of testing only "can I verify what I sign". I'm hesitant about having the default be |
Beta Was this translation helpful? Give feedback.
-
Draft code in #1104, moving discussion to PR. |
Beta Was this translation helpful? Give feedback.
-
The latest version of
cryptography
supports deterministic signing for ECDSA. Do we want to provide this indnspython
? By default or as an option?My proposal is to always sign using deterministic signatures, but could also be persuaded to implement it as an option to
dns.dnssec.sign
.Beta Was this translation helpful? Give feedback.
All reactions