Skip to content

Clarify expected performance of BoringSSL-backed numct vs nobignum for DKLS signing flows #271

Description

@toufic0710

We benchmarked DKLS/SoftSpoken signing with the default BoringSSL path and with -tags nobignum. BoringSSL does not show a clear end-to-end win, while it adds CGO/build complexity.

What was the intended benefit of introducing BoringSSL here? Was it mainly added for workloads such as the CGGMP21 library, or is it also expected to improve DKLS signing flows?

Also, is the nobignum path considered audited/supported for production use?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions