| Bugfix | |
| * Fix rsa_prepare_blinding() to retry when the blinding value is not | |
| invertible (mod N), instead of returning MBEDTLS_ERR_RSA_RNG_FAILED. This | |
| addresses a regression but is rare in practice (approx. 1 in 2/sqrt(N)). | |
| Found by Synopsys Coverity, fix contributed by Peter Kolbus (Garmin). | |
| Fixes #3647. |