Project

General

Profile

Actions

Bug #74

closed

Low entropy on several servers.

Added by Marc Dequènes almost 14 years ago. Updated over 13 years ago.

Status:
Resolved
Priority:
High
Category:
System :: Base
Start date:
2010-05-02
Due date:
% Done:

100%

Estimated time:
Patch Available:
No
Confirmed:
No
Branch:
Entity:
DuckCorp
Security:
Yes
Help Needed:

Description

With the new stats, we can see:
https://stats.duckcorp.org/graph_view.php?action=preview&host_id=0&graph_template_id=0&filter=rand

Orfeo has got a HRNG, which helps having a sufficient, even if still low, level of entropy. Daneel uses timer_entropyd, which seems to be a "not so bad" cheap generator.

As cryptography is used more and more, then more and more entropy is needed, then we need to find a solution to avoid hanging process (due to the blocking behavior of /dev/random).

Here is interresting documentation:

haveged seems to be an interresting software generator, maybe better then timer_entropyd.

Example of HRNG:

The simtec USB key seems to pass FIPS and Diehard tests and have happy users. It has Free and Linux-compatible drivers, already packaged by Debian. Maybe a good solution.

Actions

Also available in: Atom PDF