OpenSSH 3.5p1, OpenSSL0.9.7 and builtin random number collector

From: Quang Vu (quang.vu@freesurf.ch)
Date: 01/08/03


From: quang.vu@freesurf.ch (Quang Vu)
Date: 8 Jan 2003 06:44:37 -0800

Hello,

I am installing OpenSSH3.5p1 on several Solaris 8 servers which all
have the 112438-01 patch (/dev/random). All servers have been rebooted
after the patch.
I have also recompiled OpenSSL0.9.7 on these servers

On one server, I get this message on (SSH) configure:

WARNING: you are using the builtin random number collection
service. Please read WARNING.RNG and request that your OS
vendor includes kernel-based random number collection in
future versions of your OS.

My configure command for OpenSSH is:
configure --prefix=/usr/local --with-pam --without-rsh \
--disable-suid-ssh --sysconfdir=/usr/local/etc/openssh
--with-tcp-wrappers

Do I need to add some option ?
Where do I need to look for my problem ?

Thanks in advance

Quang Vu



Relevant Pages

  • Re: problems with KB951746
    ... Do any of the four servers run *without* ISA? ... What I suspect is happening is that the patch is doing what it is supposed to do. ... If your firewall is not configured to allow DNS traffic from a random source port then your recursive DNS requests are being stopped at the firewall...and you'll get the symptoms you describe. ... It is also possible, but less likely, that your ISP's DNS servers are misconfigured and are unable to reply on odd source ports. ...
    (microsoft.public.windows.server.sbs)
  • Best Practice re: patching multiple Sun Servers connected to a Hitachi SAN
    ... All Sun Servers are using Solaris 8 with Veritas Volume Manager 3.2 to ... Hitachi 9200 are under Veritas control and use VxFS filing system with large ... 8_recommended patch cluster with a date stamp of 4/20/2004. ... to install the patch cluster in single user mode with my mirrors detached ...
    (comp.unix.solaris)
  • Re: [Full-Disclosure] DCOM RPC exploit (dcom.c)
    ... But you'd still patch either way, ... of home users who don't even know what a security patch *IS*, ... But how many organisations firewall off internal servers from ... administrators have the time to watch the IDS given the number of patches they ...
    (Full-Disclosure)
  • Re: KB917537 Failing
    ... I honestly hand patch servers... ... Windows Server 2003 Hotfix KB917537 installation failed. ... The consensus among the MVPs is that SBS'ers should reboot after patch ...
    (microsoft.public.windows.server.sbs)
  • Re: KB917537 Failing
    ... This patch worked just fine on all my servers but it's obviously having issues with some servers. ... possible installer issue with the IIS patch ... To add insult to injury, if you hit the "Restart" button in the patch success dialog box rather than clicking "Later" and doing the restart manually, it fails to make the appropriate entry in the system log to document the reason for shutdown. ...
    (microsoft.public.windows.server.sbs)