Re: Open SSH v3.6.1p1
From: snake (email@example.com)
Date: 22 Apr 2003 07:43:04 -0000 From: snake <firstname.lastname@example.org> To: email@example.com('binary' encoding is not supported, stored as-is) In-Reply-To: <3E9ABDDF.13403.FD01C96@localhost>
I think it was from 0.9.7 of OpenSSL that PRNGD will be found internally
by default. When you configure OpenSSH it will say:
Random number source: OpenSSL internal ONLY
even though you specified external source. OpenSSL will find PRNGD in its
default locations (which I'm not sure where they are atm).
I've put the PRNGD socket in:
which is a default location that works with OpenSSL on Solaris.
Correct me if I'm wrong, but I think that's the problem.
Hope it works!
>Received: (qmail 18608 invoked from network); 15 Apr 2003 01:00:27 -0000
>Received: from outgoing2.securityfocus.com (HELO
> by mail.securityfocus.com with SMTP; 15 Apr 2003 01:00:27 -0000
>Received: from lists.securityfocus.com (lists.securityfocus.com
> by outgoing.securityfocus.com (Postfix) with QMQP
> id A28BB8F2D4; Mon, 14 Apr 2003 19:03:17 -0600 (MDT)
>Mailing-List: contact firstname.lastname@example.org; run by ezmlm
>Delivered-To: mailing list email@example.com
>Delivered-To: moderator for firstname.lastname@example.org
>Received: (qmail 20798 invoked from network); 14 Apr 2003 19:38:41 -0000
>From: "Alan Vidmar" <Alan.Vidmar@Colorado.edu>
>Date: Mon, 14 Apr 2003 13:55:43 -0600
>Content-type: text/plain; charset=US-ASCII
>Subject: Open SSH v3.6.1p1
>X-mailer: Pegasus Mail for Win32 (v3.12c)
>I'm trying to get Open SSH v3.6.1p1 to install on one of my AIX
>I'm following the IBM tutorial:Deploying OpenSSH on AIX
>But of course using the most recent version of OpenSSL (0.9.7b)
>and OpenSSH (3.6.1p1) due to the security problems with prior
>versions. Also I'm using GCC v3.2.1 and PRNGD v0.9.27.
>I've run into a snag when setting up the compiler for OpenSSH. I
>cannot get the compiler options to use the PRNGD (Pseudo
>Random Number Generator Daemon) instead of the OpenSSL
>internal for the "Random number source".
>Here is my config line: "./configure --sysconfdir=/etc/ssh --with-
>prngd-socket=/dev/egd-pool -- with-pid-dir=/var/tmp"
>I do have PRNGD running, so I'm not sure why it won't select it
>"I don't have time to be impatient."
>Alan R. Vidmar Assistant Director of IT
>Office of Financial Aid University of Colorado
>*** This message printed with 100% recycled electrons ***