From 3bb62ecaf42a560a39147b85b582f9c6b65e5d16 Mon Sep 17 00:00:00 2001 From: Andy Alness Date: Sat, 6 Dec 2014 13:25:44 -0800 Subject: Add explicit note about OpenSSL wrt low S values --- bip-0062.mediawiki | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) (limited to 'bip-0062.mediawiki') diff --git a/bip-0062.mediawiki b/bip-0062.mediawiki index 9d5bfe5..4e5653b 100644 --- a/bip-0062.mediawiki +++ b/bip-0062.mediawiki @@ -63,7 +63,9 @@ Below is a summary of the effects on signatures, their encoding and data pushes. The value S in signatures must be between 0x1 and 0x7FFFFFFF FFFFFFFF FFFFFFFF FFFFFFFF 5D576E73 57A4501D DFE92F46 681B20A0 (inclusive). If S is too high, simply replace it by S' = 0xFFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFE BAAEDCE6 AF48A03B BFD25E8C D0364141 - S. -The constraints on the value R is unchanged w.r.t. ECDSA, and can be between 0x1 and 0xFFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFE BAAEDCE6 AF48A03B BFD25E8C D0364140 (inclusive). +Signatures produced by the OpenSSL library are not guaranteed to be consistent with this constraint. Version 0.9.3 of the reference client provides [https://github.com/bitcoin/bitcoin/blob/0.9.3/src/key.cpp#L202-L227 an example] for detection and correction. + +The constraints on the value R are unchanged w.r.t. ECDSA, and values can be between 0x1 and 0xFFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFE BAAEDCE6 AF48A03B BFD25E8C D0364140 (inclusive). ====DER encoding==== For reference, here is how to encode signatures correctly in DER format. -- cgit v1.2.3