Subject: Re: cgd randomkey at start
To: None <tech-security@netbsd.org>
From: Christian Weniger <CWeniger@gmx.de>
List: tech-security
Date: 03/01/2005 18:06:37
> On 1109694258 seconds since the Beginning of the UNIX epoch
> "Christian Weniger" wrote:
> >
>
> >i just want to encrypt (using cgd) my swap partition and the /tmp
> >partion with a randomkey at startup. My problem is that /dev/random is
> >empty at startup and so cgd hangs and can't generate a randomkey until
> >i help and generate random data by typing on the keyboard. That's not a
> >solution because i'm going to use the computer without a keyboard.
> >
> >So how can i genrate random data without sitting in fornt of the pc?
> >Or can i use /dev/urandom for the randomkey? (i found a 2 year old mail
> >with the same
> >problem:
>
>http://groups.google.de/groups?selm=200309121954.h8CJsaFO025666%40server.duh.o
> >rg&output=gplain
> > - but it seems that there is no option "urandomkey" today).
>
> A urandom option was added after the 2.0 branch.
>
> So, you have a few options:
>
> 1. rebuild cgdconfig with current sources (which is not
> too difficult),
> 2. wait for the next release major release,
> 3. ask us to pull the changes back to the 2.0 branch and
> wait for the next minor release, or
> 4. write a program that causes lots of disk access before
> cgdconfig(1) is called in the boot sequence.
>
> Most modern computers have an entropy device, so I didn't see this
> problem when I was developing cgd(4).
>
> I'd feel a tad uncomfortable about using /dev/urandom for this,
> but it is certainly better than hanging. :)
>
> --
> Roland Dowdeswell http://www.Imrryr.ORG/~elric/
>
- i'm going to use the first option
--
Lassen Sie Ihren Gedanken freien Lauf... z.B. per FreeSMS
GMX bietet bis zu 100 FreeSMS/Monat: http://www.gmx.net/de/go/mail