Simon Josefsson simon@josefsson.org writes:
Niels Möller nisse-SamgB31n2u5IcsJQ0EH25Q@public.gmane.org writes:
- I think first there should be at least one fast and short option
available.
Makes sense, I'm working on adding slh-dsa-shake-128f.
Having 256-bit options would be nice, as a conservative long-term signature algorithm choice, any chance you could add those?
The SHA2 alternatives would be nice too, some environments have better performance for SHA2 than SHAKE.
An update: I've now added support for slh-dsa-shake-128s and slh-dsa-shake-128f to the master branch. I think I'll look at sha2-variants next, I'm also curious about their performance.
Regards, /Niels