Re: entropy + openSSL question

From: Steffen Dettmer (steffen@dett.de)
Date: 02/22/03

  • Next message: Jennifer Fountain: "Red Hat Network updates"
    Date: Sat, 22 Feb 2003 13:24:55 +0100
    From: Steffen Dettmer <steffen@dett.de>
    To: focus-linux@securityfocus.com
    
    

    * Felix Cuello wrote on Tue, Feb 18, 2003 at 22:32 -0300:
    > There´s a secure form to gain entropy in a system to generate a really
    > secure private key using openSSL??

    Maybe you can take a look how www.random.org generates random
    numbers (sampling a microphone LSB of street noise basically).
    Maybe you use some radio antenna on some frequency where no
    station sends and sample LSB slowly, or get some radioactivitiy
    detector. The conventional way of rolling a dice (or many for
    many times) can be used also, it's no joke, there are people who
    dice out payment security keys.

    > Then... I start again with my first question. there´s a good way to
    > generate entropy??? [Suppose that the machine who generates the key will
    > not have much interrupts because anybody are in front of the keyboard to
    > generate it]

    I think the solution is simple, a secure environment is not
    networked, so you need a console there anyway. Well, if the
    system activity is too low, install doom or whatever and play a
    little or watch some VideoCDs, whatever. Maybe compile something
    in the background, shouldn't be too difficult to generate some
    load.

    oki,

    Steffen

    -- 
    Dieses Schreiben wurde maschinell erstellt,
    es trägt daher weder Unterschrift noch Siegel.
    


    Relevant Pages

    • Re: The OpenSSL API
      ... if I have an application and want for it communicate ... between the black box approach and the gory-detail OpenSSL ... There is also no one best kind of security for all applications and users. ... OpenSSL is not the most secure facility, ...
      (comp.os.linux.networking)
    • Re: The OpenSSL API
      ... How does this justify the complexity of the OpenSSL API? ... OpenSSL is not the most secure facility, ...
      (comp.os.linux.networking)
    • Re: Windows Is Now More Secure Than Linux
      ... >OpenSSL is compiled into just about every 'secure' application in the Unix ... You know, a lot of people see me as a "Windows defender", mainly because I pop ... The solution, if there is one, to security problems, is to choose a supplier ...
      (comp.security.misc)
    • Re: ftp sftp, sh ssh, cp scp, ..., rpc srpc?
      ... SANS.ORG pointed out that Remote Procedure Calls are one of ... NO, there is no srpc, however there is "Secure RPC" also known ... of which are implemented in the OpenSSL toolkit. ... HTTP +SSL/TLS = HTTPS ...
      (comp.security.ssh)
    • Re: rpm/up2date question
      ... > and is the recommended stable and secure release of openssl. ... > Can anyone remark or comment to help me either correct my ignorance ...
      (Fedora)