From owner-freebsd-security@FreeBSD.ORG Tue Aug 8 13:04:55 2006 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 5B56016A4E2 for ; Tue, 8 Aug 2006 13:04:55 +0000 (UTC) (envelope-from scheidell@secnap.net) Received: from mail.secnap.com (mail.secnap.com [204.89.241.129]) by mx1.FreeBSD.org (Postfix) with ESMTP id E696443D45 for ; Tue, 8 Aug 2006 13:04:54 +0000 (GMT) (envelope-from scheidell@secnap.net) Received: from [10.70.3.3] (unknown [10.70.3.3]) by mail.secnap.com (Postfix) with ESMTP id EE55C164838; Tue, 8 Aug 2006 09:04:53 -0400 (EDT) Message-ID: <44D88BF5.9060402@secnap.net> Date: Tue, 08 Aug 2006 09:04:53 -0400 From: Michael Scheidell Organization: SECNAP Network Security User-Agent: Thunderbird 1.5.0.5 (Macintosh/20060719) MIME-Version: 1.0 To: "R. B. Riddick" References: <20060808123808.59113.qmail@web30306.mail.mud.yahoo.com> In-Reply-To: <20060808123808.59113.qmail@web30306.mail.mud.yahoo.com> X-Enigmail-Version: 0.94.0.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Cc: freebsd-security@freebsd.org Subject: Re: seeding dev/random in 5.5 X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 08 Aug 2006 13:04:55 -0000 R. B. Riddick wrote: > --- Michael Scheidell wrote: > >>> I think that during the first reboot after a fresh install >>> the kern.random.sys sysctl settings are already orderly >>> before rc.d/sshd is called... >>> >>> If yes, then sending some pings should do the trick... Or >>> not? I mean: NETWORKING should already be provided at that point... >>> >> I am not sure I understand what you are saying in the context of my >> question. >> >> > I mean: > Instead of changing a rc.d script u or ur friend could just send some pings to > the deeply buried box... > > why would that help? if (without changing rc file) /dev/random isn't seeded by networking, why wold a ping help? -- Michael Scheidell, CTO SECNAP Network Security / www.secnap.com scheidell@secnap.net / 1+561-999-5000, x 1131