From owner-freebsd-hackers Thu Oct 3 15:29: 5 2002 Delivered-To: freebsd-hackers@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 8476137B401 for ; Thu, 3 Oct 2002 15:29:02 -0700 (PDT) Received: from hotmail.com (f140.sea1.hotmail.com [207.68.163.140]) by mx1.FreeBSD.org (Postfix) with ESMTP id 26D3843E3B for ; Thu, 3 Oct 2002 15:29:02 -0700 (PDT) (envelope-from firstolasto@hotmail.com) Received: from mail pickup service by hotmail.com with Microsoft SMTPSVC; Thu, 3 Oct 2002 15:29:01 -0700 Received: from 12.235.232.75 by sea1fd.sea1.hotmail.msn.com with HTTP; Thu, 03 Oct 2002 22:29:01 GMT X-Originating-IP: [12.235.232.75] From: "Firsto Lasto" To: mark@grondar.za Cc: freebsd-hackers@FreeBSD.ORG Subject: Re: PRNG not seeded - error in non-root ssh inside 4.6.2 jails... Date: Thu, 03 Oct 2002 15:29:01 -0700 Mime-Version: 1.0 Content-Type: text/plain; format=flowed Message-ID: X-OriginalArrivalTime: 03 Oct 2002 22:29:01.0893 (UTC) FILETIME=[461E7750:01C26B2C] Sender: owner-freebsd-hackers@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG Ok, I am not sure how I can do that though - I cannot successfully run `rndcontrol -s X` inside a jail. On the other hand, I already have: rand_irqs="9 10 11 13 14" In my rc.conf on the underlying host machine, and have done several boots with that in place. So presumably I should be seeded just fine, but if I am not, I cannot change that in the jail because it seems I cannot set that (I assume it is a sysctl issue). Willing to try whatever you can think of next :) > > > I can't seed it by banging on the keyboard - it is a headless server in >a > > rack thousands of miles from me :) > > > > Perhaps there is another way to do it ? > >Yes. > >You need to find sources of entropy in interrupts. Look at a >dmesg, and note which IRQ's your network device(s) and mass >storage controller(s) (both SCSI and ATA). Use any other >irq's that aren't too busy and may be somewhat random. >Staring at a 'systat 2 -vmstat' screen (right hand side) >may give some clues. > >Then use rndcontrol(8) to set up the seeding. There is a knob >in rc.conf to make this setting survive the next reboot. > >M > > > >Date: Thu, 03 Oct 2002 21:54:30 +0100 > > > > > > > Sorry, here is the rest: > > > > > > > > Here is the output of the `dd` command using urandom: > > > > > > > > dd if=/dev/urandom of=/dev/stdout bs=512 count=1 | hexdump -C > > > > 1+0 records in > > > > 1+0 records out > > > > 00000000 a0 69 1a 7c 8f 32 e5 21 ae 7a 33 14 68 0b 8e a6 > > > > |.i.|.2.!.z3.h...| > > > > > >... etc. Looking good. > > > > > > > $ ls -l /dev/*rand* > > > > crw-r--r-- 1 root wheel 2, 3 Sep 3 21:46 /dev/random > > > > crw-r--r-- 1 root wheel 2, 4 Sep 3 21:46 /dev/urandom > > > > > >Also good. > > > > > > > > > So then, as root I ran: `chmod 0666 /dev/stdout` and then I ran >your > > > > >`dd` > > > > > > command and got: > > > > > > > > > > > > $ dd if=/dev/random of=/dev/stdout bs=512 count=1 | hexdump -C > > > > > > 0+0 records in > > > > > > 0+0 records out > > > > > > 0 bytes transferred in 0.000036 secs (0 bytes/sec) > > > > > >Can you try a few of these while furiously abusing your keyboard? > > >I'm trying to see if /dev/random can be persuaded to give _any_ > > >aoutput at all. > > > > > >Maybe do it on a vty instead of in X. > > > > > >M > > >-- > > >o Mark Murray > > >\_ > > >O.\_ Warning: this .sig is umop ap!sdn > > > > > > > > > > _________________________________________________________________ > > Chat with friends online, try MSN Messenger: http://messenger.msn.com > > >-- >o Mark Murray >\_ >O.\_ Warning: this .sig is umop ap!sdn _________________________________________________________________ Send and receive Hotmail on your mobile device: http://mobile.msn.com To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-hackers" in the body of the message