From owner-freebsd-bugs Sun Nov 11 4:55:25 2001 Delivered-To: freebsd-bugs@freebsd.org Received: from hermes.bellona.pl (pc04.bellona.pl [217.96.18.131]) by hub.freebsd.org (Postfix) with ESMTP id 0AEAA37B419 for ; Sun, 11 Nov 2001 04:55:10 -0800 (PST) Received: (from jerry@localhost) by hermes.bellona.pl (8.11.6/8.11.6) id fABCqsn06409 for freebsd-bugs@FreeBSD.org.KAV; Sun, 11 Nov 2001 13:52:54 +0100 (CET) (envelope-from jerry@bellona.pl) X-Authentication-Warning: hermes.bellona.pl: jerry set sender to jerry@bellona.pl using -f Received: from localhost (jerry@localhost) by hermes.bellona.pl (8.11.6/8.11.6) with ESMTP id fABCqqU06401 for ; Sun, 11 Nov 2001 13:52:54 +0100 (CET) (envelope-from jerry@bellona.pl) X-Authentication-Warning: hermes.bellona.pl: jerry owned process doing -bs Date: Sun, 11 Nov 2001 13:52:52 +0100 (CET) From: Jaroslaw Micota To: freebsd-bugs@FreeBSD.org Subject: low prioryty mitake with /dev/urandom acces Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-bugs@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org System Version: FreeBSD 4.4 RELEASE Prioryty: low (information) What is the problem: the /dev/urandom after instaling FreeBSD 4.4 from CD has acces rights set to crw------. This is the problem when you try to ssh to another computer (as plain user) ssh write following errors: ssh: no RSA support in libssl and libcrypto. See ssl(8). Disabling protocol version 1 DH_generate_key its hard to find (for a dumb user like me) that this is the problem with /dev/urandom access rights. When rights are set to crw-r--r-- the ssh work perfect. I think urandom is used to generate keys when you connect to another host at firs time (or something like this). Cure: changing rights to "r" in /dev/urandom When error ocures: New FreeBSD 4.4 instaled from dowloaded iso images. It doesnt happen when system is updated to 4.4 from previous versions (from CD or cvsup) Jaroslaw (Jerry) Micota PS. Great job!!! FreBSD is superb To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-bugs" in the body of the message