Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 8 May 2019 19:13:49 +0300
From:      "Andrey V. Elsukov" <bu7cher@yandex.ru>
To:        freebsd-current <freebsd-current@FreeBSD.org>
Subject:   random_sources_feed: rs_read for hardware device 'Intel Secure Key RNG' returned no entropy.
Message-ID:  <2c1eceb4-08a5-b633-2ce2-c711610db1cb@yandex.ru>

next in thread | raw e-mail | index | archive | help
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--wRyxgQHtfbYUhYl0kL1xLSPzt8GckgLSj
Content-Type: multipart/mixed; boundary="DiN3jKKx5HEjssyxti3PCaGXgVHSvaAMj";
 protected-headers="v1"
From: "Andrey V. Elsukov" <bu7cher@yandex.ru>
To: freebsd-current <freebsd-current@FreeBSD.org>
Message-ID: <2c1eceb4-08a5-b633-2ce2-c711610db1cb@yandex.ru>
Subject: random_sources_feed: rs_read for hardware device 'Intel Secure Key
 RNG' returned no entropy.

--DiN3jKKx5HEjssyxti3PCaGXgVHSvaAMj
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable

Hi,

today I updated one of my test machines and discovered that message from
the subject periodically printed in the console.

FreeBSD 13.0-CURRENT r347327=3D4f47587(svn_head) GENERIC-NODEBUG amd64
FreeBSD clang version 8.0.0 (tags/RELEASE_800/final 356365) (based on
LLVM 8.0.0)
VT(vga): resolution 640x480
CPU: Intel(R) Xeon(R) CPU E5-2660 v4@ 2.00GHz (2000.04-MHz K8-class CPU)
=2E..
real memory  =3D 68719476736 (65536 MB)
avail memory =3D 66722340864 (63631 MB)
Event timer "LAPIC" quality 600
ACPI APIC Table: <SUPERM SMCI--MB>
FreeBSD/SMP: Multiprocessor System Detected: 28 CPUs
FreeBSD/SMP: 2 package(s) x 14 core(s)
=2E..

% grep -c random /var/run/dmesg.boot
606

% grep random /var/run/dmesg.boot | head -10
__stack_chk_init: WARNING: Initializing stack protection with non-random
cookies!
random: entropy device external interface
random: registering fast source Intel Secure Key RNG
random: fast provider: "Intel Secure Key RNG"
arc4random: WARNING: initial seeding bypassed the cryptographic random
device because it was not yet seeded and the knob
'bypass_before_seeding' was enabled.
random_sources_feed: rs_read for hardware device 'Intel Secure Key RNG'
returned no entropy.
random_sources_feed: rs_read for hardware device 'Intel Secure Key RNG'
returned no entropy.
random_sources_feed: rs_read for hardware device 'Intel Secure Key RNG'
returned no entropy.
random_sources_feed: rs_read for hardware device 'Intel Secure Key RNG'
returned no entropy.
random_sources_feed: rs_read for hardware device 'Intel Secure Key RNG'
returned no entropy.

% sysctl -a | grep -v random_sources_feed | grep rand
kern.fallback_elf_brand: -1
device	random
device	rdrand_rng
kern.randompid: 0
kern.elf32.fallback_brand: -1
kern.elf64.fallback_brand: -1
kern.random.fortuna.minpoolsize: 64
kern.random.harvest.mask_symbolic:
PURE_RDRAND,[UMA],[FS_ATIME],SWI,INTERRUPT,NET_NG,[NET_ETHER],NET_TUN,MOU=
SE,KEYBOARD,ATTACH,CACHED
kern.random.harvest.mask_bin: 000000010000000111011111
kern.random.harvest.mask: 66015
kern.random.use_chacha20_cipher: 0
kern.random.block_seeded_status: 0
kern.random.random_sources: 'Intel Secure Key RNG'
kern.random.initial_seeding.disable_bypass_warnings: 0
kern.random.initial_seeding.arc4random_bypassed_before_seeding: 1
kern.random.initial_seeding.read_random_bypassed_before_seeding: 0
kern.random.initial_seeding.bypass_before_seeding: 1
net.inet.ip.portrange.randomtime: 45
net.inet.ip.portrange.randomcps: 10
net.inet.ip.portrange.randomized: 1
net.inet.ip.random_id_total: 0
net.inet.ip.random_id_collisions: 0
net.inet.ip.random_id_period: 0
net.inet.ip.random_id: 0
net.key.int_random: 60
debug.fail_point.status_fill_kinfo_vnode__random_path: off
debug.fail_point.fill_kinfo_vnode__random_path: off
debug.fail_point.status_random_fortuna_pre_read: off
debug.fail_point.random_fortuna_pre_read: off
security.stack_protect.permit_nonrandom_cookies: 1

--=20
WBR, Andrey V. Elsukov


--DiN3jKKx5HEjssyxti3PCaGXgVHSvaAMj--

--wRyxgQHtfbYUhYl0kL1xLSPzt8GckgLSj
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Comment: Using GnuPG with Thunderbird - https://www.enigmail.net/

iQEzBAEBCAAdFiEE5lkeG0HaFRbwybwAAcXqBBDIoXoFAlzTAD0ACgkQAcXqBBDI
oXo8iwgAvlFx/fh0TdisO08oP3Jg2MDN6wnJJp8xy6tqF5AIB3nuZ/uWxz53OxGC
k673SkYCbTCVPDbvPl2S5zNXYa9aBNf9448CWBpSCKhGPUuIUNquLME1F4uvxyaU
BVS9LSqHS1rQ31m/S55vXabtLhgFQax2ogicAyC9TOvsPTITQcGEzMHzSd/tMd5/
e2yF0mQsInUswk/6i9j3HRv7fvHWn/bu7X54OfNswh7QyRSkjJG44DdahF//ADTM
0cpKZ8eEVlB7L3+D8o2C2xCAvVdIRUxmX9eHZd2LONIutQQIiqL5kbjLeqn1NHHP
Vpp9Ytwdo48aN+TZayfr1UB5rbPXUA==
=jHAt
-----END PGP SIGNATURE-----

--wRyxgQHtfbYUhYl0kL1xLSPzt8GckgLSj--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?2c1eceb4-08a5-b633-2ce2-c711610db1cb>