+
+ c.r = &rand_global;
+ h = gkcdsa_beginhash(&c);
+ GH_HASH(h, v[3].buf, v[3].len);
+ m = GH_DONE(h, 0);
+ GH_DESTROY(h);
+ gkcdsa_sign(&c, &ss, m, 0);
+ if (gkcdsa_verify(&c, &ss, m)) {
+ ok = 0;
+ fprintf(stderr, "*** sign cross-check failed!\n");
+ fprintf(stderr, "*** group: %s\n", v[0].buf);
+ fprintf(stderr, "*** hash: %s\n", c.h->name);
+ showmp("private key", c.u, 16);
+ showge(c.g, "public key", c.p);
+ fprintf(stderr, "*** message: `%s'\n", v[3].buf);
+ fprintf(stderr, "*** computed r = ");
+ type_hex.dump(&d, stderr); putc('\n', stderr);
+ showmp("computed s", ss.s, 16);
+ }
+
+ mp_drop(s.s); mp_drop(x); mp_drop(k); dstr_destroy(&d); mp_drop(ss.s);
+ mp_drop(c.u); G_DESTROY(c.g, c.p); G_DESTROYGROUP(c.g);