Re: hsmbully considered harmful?

Rick van Rein rick at openfortress.nl
Tue Aug 18 09:13:52 UTC 2009


> We've all weard the joke; Hey Doc, it hurts when I do this. and the  
> doctor says; Then don't do that!

Of course.  But the idea of the initiation test is to ensure security,
which implies running tests out of the ordinary.  It's easy of course
to make this an optional test and add a note about it in the man page.
It sounds like a topic for this afternoon's phone meeting.

> having said that, we should of course report this bug to Sun so it can  
> be fixed.

Absolutely.  Will you talk to them, or shall I?  I don't own their HSM,
so it might be a bit weird if I'd do it.  Just pass on the code of
hsmbully to them, I'd propose.

> the problem is that when it crashes it reboots, so I'd rather not  
> continue testing on this machine - it is the main development machine  
> for the project. I think we should let Sun debug this for us.

Uck -- that's bad.  Understood, let Sun worry about it.


