From owner-freebsd-security@FreeBSD.ORG Tue Aug 8 23:48:52 2006 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 705E716A4DA for ; Tue, 8 Aug 2006 23:48:52 +0000 (UTC) (envelope-from dougb@FreeBSD.org) Received: from mail2.fluidhosting.com (mx23.fluidhosting.com [204.14.89.6]) by mx1.FreeBSD.org (Postfix) with SMTP id E3A7543D45 for ; Tue, 8 Aug 2006 23:48:51 +0000 (GMT) (envelope-from dougb@FreeBSD.org) Received: (qmail 20195 invoked by uid 399); 8 Aug 2006 23:48:51 -0000 Received: from localhost (HELO ?192.168.0.3?) (dougb@dougbarton.us@127.0.0.1) by localhost with SMTP; 8 Aug 2006 23:48:51 -0000 Message-ID: <44D922E0.5050005@FreeBSD.org> Date: Tue, 08 Aug 2006 16:48:48 -0700 From: Doug Barton Organization: http://www.FreeBSD.org/ User-Agent: Thunderbird 1.5.0.5 (X11/20060729) MIME-Version: 1.0 To: Kevin Day References: <44D7B860.5080906@secnap.net> <44D8CB3C.5090906@FreeBSD.org> <45114657-81B6-4618-BFBB-7BD2EA4D0418@dragondata.com> In-Reply-To: <45114657-81B6-4618-BFBB-7BD2EA4D0418@dragondata.com> X-Enigmail-Version: 0.94.0.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Cc: freebsd-security@freebsd.org Subject: Re: seeding dev/random in 5.5 X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 08 Aug 2006 23:48:52 -0000 Kevin Day wrote: > Maybe sysinstall could be collecting entropy during the installation and > use that for an initial seed if the timeout happens? It wouldn't be > perfect, but it'd be better than killing ssh. The patches you sent to implement this option didn't come through to the mailing list, could you resend them please? :) Seriously though, a lot of people looked at this problem when yarrow was introduced, and no solution became immediately apparent. So, if someone wants to take a crack at implementing something, knock yourself out. Doug -- This .signature sanitized for your protection