[Cryptography] Standard exponents in RSA

Ralph Holz ralph-cryptometzger at ralphholz.de
Wed Oct 30 18:47:12 EDT 2013


Hi,

>> the two most common exponents that one finds in X.509 RSA certs are
>> 65537 and 17 -- in my data, they account for near 100%. Have these
>> been chosen as the result of some standardisation and was there some
>> cryptographic reasoning behind it, or is it simply that any exponent
>> will do? Any performance issues?
> 
> NIST SP 800-56B says so:
> http://csrc.nist.gov/publications/nistpubs/800-56B/sp800-56B.pdf
> 
> (or to be precise, it says minimum size 65537 - so most people seem to
> choose the minimum, which is also fast in computation)

Excellent, thanks!

Ralph



More information about the cryptography mailing list