Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Clarification: OpenSSH entropy sources?

From: Ben Lindstrom <mouring(at)etoh.eviladmin.org>
Date: Fri May 02 2003 - 14:38:33 EDT

OpenSSH does the following behavior.

  1. Checks of OpenSSL can seed itself. If can use it.
  2. If it can't and no ssh prng helper is configured, fail.
  3. if ssh prng helper is configured try to use it.
  4. if ssh prng helper can not produce enough, fail.

So it will always try and use OpenSSL provided entropy before trying the ssh-prng-helper. This provides the ability for platforms like Solaris that just gained a /dev/random to use it without a recompile.

  • Ben

On Fri, 2 May 2003, Jonathan Sturges wrote:

> I got no reply from comp.security.ssh so I'm forwarding it to the list.
Received on Fri May 2 15:06:53 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:58 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library