Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 4 Oct 2002 11:06:25 -0400
From:      Vivek Khera <khera@kcilink.com>
To:        stable@freebsd.org
Subject:   Re: IPSEC warning -- what are alternatives?
Message-ID:  <15773.44657.957038.146065@onceler.kciLink.com>
In-Reply-To: <3D9DAB2D.3060306@potentialtech.com>
References:  <15773.39612.629029.716325@onceler.kciLink.com> <3D9DAB2D.3060306@potentialtech.com>

next in thread | previous in thread | raw e-mail | index | archive | help
>>>>> "BM" == Bill Moran <wmoran@potentialtech.com> writes:

BM> Read "man 4 random", and pay special attention to the paragraph about
BM> urandom and random.

Thanks for the tip.  I read through that, but I don't see anywhere how
to tell IPsec which random source to use, other than some patches to
openssl to make it use a crypto hardware source.

I already have rand_irqs set in my rc.conf to my ethernet and disk
controller interrupts, so /dev/random should do pretty well.

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-stable" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?15773.44657.957038.146065>