[Cryptography] Timing of saving RNG state
Viktor Dukhovni
cryptography at dukhovni.org
Fri Jan 3 16:05:13 EST 2014
On Fri, Jan 03, 2014 at 02:49:01PM -0500, Theodore Ts'o wrote:
> > Speaking of the timing of RNG state save/restore, Nico Williams
> > observes that it would be prudent to save state not only on (clean)
> > shutdown, but also at startup, immediately after the previously
> > saved seed is loaded. That way after a power-outage, panic, ...
> > the seed does not start in the same state as on previous boot.
>
> It's such a good idea I recommened it almost a decade ago in the Linux
> kernel sources. :-)
>
> And it's such a good idea Debian and Ubuntu's /etc/init.d/urandom also
> does this.
Good to know, thanks. We must have been looking at some older
systems last time this issue came up.
--
Viktor.
More information about the cryptography
mailing list