+You can also use elliptic-curve DSA. The key-generation runes are more
+complicated in this case. For example,
+
+@example
+key -k /etc/become/become.key add -aec -Cnist-p256 -e"now + 1 year" \
+ become sig=ecdsa hash=sha256
+@end example
+The @code{hash=sha256} is not required, but it's good to have a hash function
+as strong as your curve. See the manpage for @code{key} for more details
+about generating elliptic curve keys, and for the kinds of curves supported.
+