RFC Errata
RFC 8032, "Edwards-Curve Digital Signature Algorithm (EdDSA)", January 2017
Source of RFC: IRTFSee Also: RFC 8032 w/ inline errata
Errata ID: 8197
Status: Verified
Type: Technical
Publication Format(s) : TEXT
Reported By: Nawras H. Sabbry
Date Reported: 2024-12-03
Verifier Name: Nick Sullivan
Date Verified: 2026-01-27
Section 5.1.4 says:
However, using the formulas described in Section 3.2 of [Edwards-revisited] and in [EFD-TWISTED-DBL] saves a few smaller operations.
It should say:
However, using the formulas described in Section 3.3 of [Edwards-revisited] and in [EFD-TWISTED-DBL] saves a few smaller operations.
Notes:
In RFC 8032 Section 5.1.4, the reference to "formulas described in Section 3.2 of [Edwards-revisited]" is incorrect. Section 3.2 of [Edwards-revisited] discusses Dedicated Addition, not doubling. The doubling formulas mentioned in RFC 8032 actually appear in Section 3.3 of [Edwards-revisited], under Dedicated Doubling.
--VERIFIER NOTE--
Verified. Section 5.1.4 discusses doubling formulas from Edwards-revisited. Section 3.2 of that paper covers addition formulas; Section 3.3 covers doubling formulas. The reference should be Section 3.3. Confirmed via Explicit Formulas Database at hyperelliptic.org.
