Re: seeding dev/random in 5.5
- From: Brooks Davis <brooks@xxxxxxxxxxxxxxxxxx>
- Date: Wed, 9 Aug 2006 08:08:42 -0500
On Wed, Aug 09, 2006 at 12:17:35AM -0700, R. B. Rid*** wrote:
--- Doug Barton <dougb@xxxxxxxxxxx> wrote:
The patches you sent to implement this option didn't come through to theSince this is the security mailing list, I would like to direct the attention
mailing list, could you resend them please? :)
Seriously though, a lot of people looked at this problem when yarrow was
introduced, and no solution became immediately apparent. So, if someone
wants to take a crack at implementing something, knock yourself out.
on the following points:
* I see in the CD-procedure the problem, that a postman, who is more
sophisticated than in Leslie Nielsen's "Naked Gun 33 1/3" movie, might exchange
the media, so that u let ur Netherlandish install something u dont know and/or
like. Workaround: Do you use a checksum over the media (`md5 < /dev/acd0`) and
transmit those checksum on a different way (maybe email)?
* I received a private communication yesterday about this matter. But the list
did not. I will cite (not litterally) a little bit out of that message: Since
you do not know anything about the remotely created host-key, u cannot connect
safely to the freshly installed box, because: You do not even know the
signature of the new host-key, so that if u connect to the wrong box u would
not even known. Workaround: You could give all hosts the same well-known
host-key (via your install-image-CD) and then u could change the host-key in a
remotely controlled way individually and note down the signature? Maybe my
secret informer (lets call him Rasmus or RK) wants to come public... :-)
These are valid if probably overly paranoid points. :)
* But what if the postman (see first point) know already the host-key from
reading the CD? Then he could log in to ur boxes...
This isn't true. The host key lets you impersonate the host. It
does not do anything related to log in (unless you use host based
auth).
-- Brooks
Attachment:
pgpj3fM6OCvh2.pgp
Description: PGP signature
- Follow-Ups:
- Re: seeding dev/random in 5.5
- From: R. B. Rid***
- Re: seeding dev/random in 5.5
- From: fwaggle
- Re: seeding dev/random in 5.5
- References:
- Re: seeding dev/random in 5.5
- From: Doug Barton
- Re: seeding dev/random in 5.5
- From: R. B. Rid***
- Re: seeding dev/random in 5.5
- Prev by Date: Re: seeding dev/random in 5.5
- Next by Date: Re: seeding dev/random in 5.5
- Previous by thread: Re: seeding dev/random in 5.5
- Next by thread: Re: seeding dev/random in 5.5
- Index(es):