[148915] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: [Cryptography] Timing of saving RNG state

daemon@ATHENA.MIT.EDU (Viktor Dukhovni)
Fri Jan 3 17:48:18 2014

X-Original-To: cryptography@metzdowd.com
Date: Fri, 3 Jan 2014 21:05:13 +0000
From: Viktor Dukhovni <cryptography@dukhovni.org>
To: cryptography@metzdowd.com
In-Reply-To: <20140103194901.GA9591@thunk.org>
Reply-To: cryptography@metzdowd.com
Errors-To: cryptography-bounces+crypto.discuss=bloom-picayune.mit.edu@metzdowd.com

On Fri, Jan 03, 2014 at 02:49:01PM -0500, Theodore Ts'o wrote:

> > Speaking of the timing of RNG state save/restore, Nico Williams
> > observes that it would be prudent to save state not only on (clean)
> > shutdown, but also at startup, immediately after the previously
> > saved seed is loaded.  That way after a power-outage, panic, ...
> > the seed does not start in the same state as on previous boot.
> 
> It's such a good idea I recommened it almost a decade ago in the Linux
> kernel sources.  :-)
> 
> And it's such a good idea Debian and Ubuntu's /etc/init.d/urandom also
> does this.

Good to know, thanks.  We must have been looking at some older
systems last time this issue came up.

-- 
	Viktor.
_______________________________________________
The cryptography mailing list
cryptography@metzdowd.com
http://www.metzdowd.com/mailman/listinfo/cryptography

home help back first fref pref prev next nref lref last post