gnutls-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [gnutls-dev] Feature request: not really random session keys


From: Werner Koch
Subject: Re: [gnutls-dev] Feature request: not really random session keys
Date: Mon, 30 Jan 2006 15:21:34 +0100
User-agent: Gnus/5.110004 (No Gnus v0.4) Emacs/21.4 (gnu/linux)

On Mon, 30 Jan 2006 14:18:43 +0100, Florian Weimer said:

> Why not fix /dev/random instead, and add the functionality which is
> missing there?  With all the trouble with threading, forking, and so
> on, it might make sense to put this into the kernel.

Sure.  That was orginally Ted Tso's plan but he could not get a solid
RNG into the kernel because the kernel hackers required to amke
/dev/random optional and Ted's plan was to have a solid RNG in the
kernel as a standard service.

With all the changes to the RNG (or better the so-called entropy
sources) I still feel safer to add some extra processing to
/dev/random.

Some OSes don't have a /dev/random or worse a predictable one (some OS X).
Thus we need to do it on our own to be portable.


Salam-Shalom,

   Werner






reply via email to

[Prev in Thread] Current Thread [Next in Thread]