When generating private key and nonce for ECDSA, use rejection sampling. Note: SP uses this algorithm