Zoltan Fridrich zfridric@redhat.com writes:
Do you think it would be reasonable to drop the sha2 variants in the first iteration?
Yes, I think its fine to just have shake variants in the first iteration.
I'm leaning towards starting with slh_dsa_shake_128s based on my rather minimal code (about 1000 lines, including comments), and iterate from there.
Regards, /Niels