[Opendnssec-develop] True Random Number Generator

Rickard Bondesson Rickard.Bondesson at iis.se
Thu Jan 8 13:41:07 UTC 2009


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

> Sorry, I wasn't clear. They were two separate threads of 
> thought. What I meant is an application?? or kernel module?? 
> that gets random data via libusb and presents it as something 
> like /dev/random to the applications that might want to use 
> it. So any application that allows you to specify the random 
> device (like the -r option to dnssec-keygen) can use it.

Yeah. That is a good idea.

> I agree this should only be done if it is a question of 
> supporting the correct attributes or something simple. Adding 
> certs or symmetric keys is too much. I did try getting the 
> opensc engine to talk to softHSM and it kept complaining 
> about things (they seemed minor) but I didn't note down what 
> they were - I will try again and post a summary.

Ohh. Bug reports are always nice :)

// Rickard
-----BEGIN PGP SIGNATURE-----
Version: 9.8.3 (Build 4028)
Charset: utf-8

wsBVAwUBSWYCc+CjgaNTdVjaAQi3DQf/aJEYzGuLMV6/Fc6l/aF/7Ur9wHOhatpM
i6azbCCyLWaIDA1Jkov03x2dlP/j6w2f8O+gclz7wtmNa5G7EENpJABQ3XAaVdqK
CxemNV366g1Xgh7uwg8hi7k67VouErthe7DtmLFUCT6HzdqaOy07gluJiP65lZEk
l6Es4H/4ooamH7qk1af7Kp6QCDxzc2XU0LJrK0iURJ9jYHk0YxhoELXf/pyj0h9x
h+PNGie0ZGj0Hhg9Amt4ECOE8Dv4BKMualyuewb3nHplQC5V4HSO05WMrVAegphH
0jHaPidHYvEgwFPBopfYq5UW9dpdrco+6A6dNYeeXdzf72o66NB7lQ==
=O0OZ
-----END PGP SIGNATURE-----



More information about the Opendnssec-develop mailing list