Date: Thu, 17 Apr 2003 10:01:00 +0100 From: Matthew Seaman <m.seaman@infracaninophile.co.uk> To: Gary D Kline <kline@thought.org> Cc: freebsd-questions@freebsd.org Subject: Re: BIND qustionS Message-ID: <20030417090100.GC90819@happy-idiot-talk.infracaninophi> In-Reply-To: <20030417063249.GA660@tao.thought.org> References: <20030417005140.GA99929@tao.thought.org> <87y929dg36.fsf@pooh.honeypot.net> <20030417063249.GA660@tao.thought.org>
next in thread | previous in thread | raw e-mail | index | archive | help
--jL2BoiuKMElzg3CS
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
On Wed, Apr 16, 2003 at 11:32:49PM -0700, Gary D Kline wrote:
> On Wed, Apr 16, 2003 at 09:15:41PM -0500, Kirk Strauser wrote:
> > At 2003-04-17T00:51:40Z, Gary D Kline <kline@thought.org> writes:
> >=20
> > > After upgrading to BIND-9.2.2, I bumped into the following output mes=
sage
> > > that I don't understand.
> >=20
> > Run `rndc-confgen' to generate the key (and a reasonable rndc.conf to go
> > with it).
>=20
>=20
> As roor I'm exec'd rndc-confgen (with various switches). It
> seems to hang, or be sleeping. Do you know what may be happening
> here?
It's trying to read some random data out of /dev/random, but your
system doesn't have enough sufficiently good entropic sources configured
that it can provide as much as rndc-confgen wants.
Take a look at:
i) The '-r' option to rndc-confgen. If you say:
rndc-confgen -a -r keyboard
randomness will be derived by your typing at the keyboard.
ii) The rc.conf 'rand_irqs' variable and the the rndcontrol(8) man
page. To select some good IRQs to use as sources of randomness
look at the 'systat -vmstat' display, specifically the table of
interrupts on the right hand side. Hint: the clk interrupt is no
good for generating randomness as it fires at regular intervals.
Cheers,
Matthew
--=20
Dr Matthew J Seaman MA, D.Phil. 26 The Paddocks
Savill Way
PGP: http://www.infracaninophile.co.uk/pgpkey Marlow
Tel: +44 1628 476614 Bucks., SL7 1TH UK
--jL2BoiuKMElzg3CS
Content-Type: application/pgp-signature
Content-Disposition: inline
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (FreeBSD)
iD8DBQE+nm1MdtESqEQa7a0RApzKAJ944+OacUn7G8AnLKA6xZKmmIG6LQCfXFeu
jPKyiNiXRdMeST+t2iVXqmk=
=pO6i
-----END PGP SIGNATURE-----
--jL2BoiuKMElzg3CS--
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20030417090100.GC90819>
