[Cryptography] Timing of saving RNG state

Viktor Dukhovni cryptography at dukhovni.org
Fri Jan 3 16:05:13 EST 2014


On Fri, Jan 03, 2014 at 02:49:01PM -0500, Theodore Ts'o wrote:

> > Speaking of the timing of RNG state save/restore, Nico Williams
> > observes that it would be prudent to save state not only on (clean)
> > shutdown, but also at startup, immediately after the previously
> > saved seed is loaded.  That way after a power-outage, panic, ...
> > the seed does not start in the same state as on previous boot.
> 
> It's such a good idea I recommened it almost a decade ago in the Linux
> kernel sources.  :-)
> 
> And it's such a good idea Debian and Ubuntu's /etc/init.d/urandom also
> does this.

Good to know, thanks.  We must have been looking at some older
systems last time this issue came up.

-- 
	Viktor.


More information about the cryptography mailing list