cacert-sysadm AT lists.cacert.org
Subject: CAcert System Admins discussion list
List archive
- From: Ian G <iang AT iang.org>
- To: cacert-sysadm AT lists.cacert.org
- Subject: [Cacert-sysadm] openSSL/debian debacle -> random numbers for Security Manual
- Date: Thu, 29 May 2008 17:30:06 +0200
- List-archive: <http://lists.cacert.org/pipermail/cacert-sysadm>
- List-id: CAcert System Admins discussion list <cacert-sysadm.lists.cacert.org>
With the OpenSSL/debian debacle fresh in our minds, it seems that this would be a good time to think about CAcert's need for good random numbers.
It has frequently been pointed out that random numbers are devilishly difficult to deal with, something made apparent with the recent events. To deal with them requires some sort of process and/or check and/or alternate sources, it would seem.
As Pat is writing the Security Manual, it would seem that this is the place for such a thing; does anyone have a view on a simple procedure for creating a sequence of RNs that is useful for the tasks?
I'm expecting to see something that overcomes simple things like "OpenSSL delivers all zeros and we didn't notice..."
I'd guess there are two parts: root keys (high quality needed) and routine protocol work (OpenSSL/httpd, SSH, etc, so "regular" randoms needed, whatever that means).
Any thoughts? Pat, is there an easy place for this in the SM?
http://wiki.cacert.org/wiki/SecurityManual
iang
- [Cacert-sysadm] openSSL/debian debacle -> random numbers for Security Manual, Ian G, 05/29/2008
- Re: [Cacert-sysadm] openSSL/debian debacle -> random numbers for Security Manual, Pat Wilson, 05/29/2008
- Re: [Cacert-sysadm] openSSL/debian debacle -> random numbers for Security Manual, Teus Hagen, 05/30/2008
- Re: [Cacert-sysadm] openSSL/debian debacle -> random numbers for Security Manual, Philipp Gühring, 05/30/2008
- Re: [Cacert-sysadm] openSSL/debian debacle -> random numbers for Security Manual, Teus Hagen, 05/30/2008
- Re: [Cacert-sysadm] openSSL/debian debacle -> random numbers for Security Manual, Sam Johnston, 05/30/2008
- Re: [Cacert-sysadm] openSSL/debian debacle -> random numbers for Security Manual, Ian G, 05/30/2008
- Re: [Cacert-sysadm] openSSL/debian debacle -> random numbers for Security Manual, Philipp Gühring, 05/30/2008
- Re: [Cacert-sysadm] openSSL/debian debacle -> random numbers for Security Manual, Ian G, 05/30/2008
- Re: [Cacert-sysadm] openSSL/debian debacle -> random numbers for Security Manual, Philipp Gühring, 05/30/2008
- Re: [Cacert-sysadm] openSSL/debian debacle -> random numbers for Security Manual, Teus Hagen, 05/30/2008
- Re: [Cacert-sysadm] openSSL/debian debacle -> random numbers for Security Manual, Kim Holburn, 05/29/2008
- Re: [Cacert-sysadm] openSSL/debian debacle -> random numbers for Security Manual, Kim Holburn, 05/29/2008
- Re: [Cacert-sysadm] openSSL/debian debacle -> random numbers for Security Manual, Pat Wilson, 05/29/2008
Archive powered by MHonArc 2.6.16.