From 6f3e9754ef9446cb8a9f98e593aed23a730c4c10 Mon Sep 17 00:00:00 2001 From: Laurent Bercot Date: Thu, 15 Sep 2016 11:48:18 +0000 Subject: Add s6-fillurandompool --- doc/s6-fillurandompool.html | 74 +++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 74 insertions(+) create mode 100644 doc/s6-fillurandompool.html (limited to 'doc/s6-fillurandompool.html') diff --git a/doc/s6-fillurandompool.html b/doc/s6-fillurandompool.html new file mode 100644 index 0000000..777307e --- /dev/null +++ b/doc/s6-fillurandompool.html @@ -0,0 +1,74 @@ + + + + + + s6-linux-utils: the s6-fillurandompool program + + + + + + +

+s6-linux-utils
+Software
+skarnet.org +

+ +

The s6-fillurandompool program

+ +

+s6-fillurandompool blocks until the machine's +/dev/urandom entropy pool is filled up. Then it exits. +

+ +

Interface

+ +
+     s6-fillurandompool
+
+ +

Rationale

+ +

+ For some reason, Linux has two separate entropy pools: one for +/dev/random and one for /dev/urandom. +

+ +

+ Reading from /dev/random blocks when its entropy pool is +not full enough, so it will never return weak random data. (Reading +from /dev/random is overkill anyway, and +you +should not be doing it.) +

+ +

+ However, reading from /dev/urandom (which +you should be doing) +will not block, even though the entropy pool may not have been +initialized yet. That's the only insecure thing about it: at boot time, +/dev/urandom may return weak random data, until its entropy +pool has filled up. +

+ +

+ s6-fillurandompool is meant to address this issue. Call it once +early on in your boot scripts, before you need any serious random data; +when it exits, the /dev/urandom pool has been properly initialized, +and it is now safe to read from /dev/urandom every time you need +random data, until the machine shuts down. +

+ +

Notes

+ + + + + -- cgit v1.3.1