<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: /dev/random &amp;amp; SSH in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898677#M748321</link>
    <description>I'm an HP-UX 11.00 administrator and I'm interested in getting /dev/random on my boxes.&lt;BR /&gt;&lt;BR /&gt;I think HP is very dark in this kind of issues. I also think HP is slow for implementing easy solutions available yes in other Unix environments (as Linux). For instance, it is possible create /dev/zero in HP-UX 11.00 but I cannot find any man page where it is described.&lt;BR /&gt;&lt;BR /&gt;Other issue may be internet security... HP startet support for OpenSSH but HP doesn't support PGP (other interesting security product)&lt;BR /&gt;</description>
    <pubDate>Fri, 07 Feb 2003 09:16:48 GMT</pubDate>
    <dc:creator>Jdamian</dc:creator>
    <dc:date>2003-02-07T09:16:48Z</dc:date>
    <item>
      <title>/dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898673#M748317</link>
      <description>Hi,&lt;BR /&gt;I've written up a short paper on using /dev/random with SSH.  (Installing, performance &amp;amp; security). I'm interested in feedback regarding the article and especially any experiences other have had in using /dev/random in a production environment (with or without SSH). &lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://newfdawg.com/SSHpart5.htm" target="_blank"&gt;http://newfdawg.com/SSHpart5.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;TIA.&lt;BR /&gt;- Chris&lt;BR /&gt;</description>
      <pubDate>Thu, 06 Feb 2003 17:09:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898673#M748317</guid>
      <dc:creator>Chris Wong</dc:creator>
      <dc:date>2003-02-06T17:09:20Z</dc:date>
    </item>
    <item>
      <title>Re: /dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898674#M748318</link>
      <description>This is exactly what we are looking for, BUT&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;It's for 11i only, and we need it for 11.00. Do you have solutions for 11.00 too? Please?&lt;BR /&gt;&lt;BR /&gt;Enjoy, have FUN! H.Merijn</description>
      <pubDate>Thu, 06 Feb 2003 17:16:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898674#M748318</guid>
      <dc:creator>H.Merijn Brand (procura</dc:creator>
      <dc:date>2003-02-06T17:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: /dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898675#M748319</link>
      <description>Maybe someone from HP can answer the question if/when /dev/random will be available for 11.0.&lt;BR /&gt;&lt;BR /&gt;Otherwise... I'd say update-ux.  :-&amp;gt;&lt;BR /&gt;&lt;BR /&gt;- Chris</description>
      <pubDate>Thu, 06 Feb 2003 17:24:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898675#M748319</guid>
      <dc:creator>Chris Wong</dc:creator>
      <dc:date>2003-02-06T17:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: /dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898676#M748320</link>
      <description>*we* could, but *our customers* can't. They will have to use it too. :/&lt;BR /&gt;&lt;BR /&gt;Enjoy, have FUN! H.Merijn</description>
      <pubDate>Thu, 06 Feb 2003 17:41:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898676#M748320</guid>
      <dc:creator>H.Merijn Brand (procura</dc:creator>
      <dc:date>2003-02-06T17:41:33Z</dc:date>
    </item>
    <item>
      <title>Re: /dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898677#M748321</link>
      <description>I'm an HP-UX 11.00 administrator and I'm interested in getting /dev/random on my boxes.&lt;BR /&gt;&lt;BR /&gt;I think HP is very dark in this kind of issues. I also think HP is slow for implementing easy solutions available yes in other Unix environments (as Linux). For instance, it is possible create /dev/zero in HP-UX 11.00 but I cannot find any man page where it is described.&lt;BR /&gt;&lt;BR /&gt;Other issue may be internet security... HP startet support for OpenSSH but HP doesn't support PGP (other interesting security product)&lt;BR /&gt;</description>
      <pubDate>Fri, 07 Feb 2003 09:16:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898677#M748321</guid>
      <dc:creator>Jdamian</dc:creator>
      <dc:date>2003-02-07T09:16:48Z</dc:date>
    </item>
    <item>
      <title>Re: /dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898678#M748322</link>
      <description>Sorry, but there are currently no plans to support /dev/random on 11.00. &lt;BR /&gt;&lt;BR /&gt;As for /dev/zero, HP-UX 11.22 a.k.a 11i V1.6 does formally document /dev/zero at last.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 07 Feb 2003 18:47:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898678#M748322</guid>
      <dc:creator>doug hosking</dc:creator>
      <dc:date>2003-02-07T18:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: /dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898679#M748323</link>
      <description>Damian,&lt;BR /&gt;&lt;BR /&gt;I can't remember where I picked this up, but&lt;BR /&gt;making /dev/zero goes like this :&lt;BR /&gt;&lt;BR /&gt;------------------------------&lt;BR /&gt;#!/bin/sh&lt;BR /&gt;&lt;BR /&gt;# major/minor for HPUX 11.X&lt;BR /&gt;mknod /dev/zero c 3 4&lt;BR /&gt;chown bin:bin /dev/zero&lt;BR /&gt;chmod 666 /dev/zero&lt;BR /&gt;-------------------------------&lt;BR /&gt;&lt;BR /&gt;Though I don't know what the results of writing to /dev/zero might be ... reading &lt;BR /&gt;from it works fine.&lt;BR /&gt;&lt;BR /&gt;-rg-</description>
      <pubDate>Mon, 10 Feb 2003 10:20:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898679#M748323</guid>
      <dc:creator>Roger Crettol</dc:creator>
      <dc:date>2003-02-10T10:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: /dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898680#M748324</link>
      <description>We do have it here for 11i, I do not know if it will work for 11.0&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=KRNG11I" target="_blank"&gt;http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=KRNG11I&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Berlene</description>
      <pubDate>Tue, 18 Feb 2003 22:45:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898680#M748324</guid>
      <dc:creator>Berlene Herren</dc:creator>
      <dc:date>2003-02-18T22:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: /dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898681#M748325</link>
      <description>Berlene, as released it will NOT work on 11.00. This has heavy dependencies on kernel internals and specific kernel patches that vary from release to release.  The primary author of the code in question sat directly across the hall from me.  Trust me. :-)&lt;BR /&gt;</description>
      <pubDate>Tue, 18 Feb 2003 23:28:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898681#M748325</guid>
      <dc:creator>doug hosking</dc:creator>
      <dc:date>2003-02-18T23:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: /dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898682#M748326</link>
      <description>Thanks, Doug, glad you said that.  But it is there for 11i, and does not come with the native OS.  &lt;BR /&gt;&lt;BR /&gt;Berlene</description>
      <pubDate>Wed, 19 Feb 2003 12:45:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898682#M748326</guid>
      <dc:creator>Berlene Herren</dc:creator>
      <dc:date>2003-02-19T12:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: /dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898683#M748327</link>
      <description>Sorry, I didn't mean to suggest it could never work on 11.00 with enough effort; just that the currently released bits don't work on 11.00 and that there are currently no plans to backport the code to 11.00.</description>
      <pubDate>Wed, 19 Feb 2003 15:47:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898683#M748327</guid>
      <dc:creator>doug hosking</dc:creator>
      <dc:date>2003-02-19T15:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: /dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898684#M748328</link>
      <description>&lt;BR /&gt;Thanks for the install howto, but it seems not to describe the current KRNG11i package.&lt;BR /&gt;&lt;BR /&gt;swlist shows&lt;BR /&gt;  KRNG11i                       B.11.11.06     HP-UX 11.11 Strong Random Number Generator &lt;BR /&gt;&lt;BR /&gt;However, no /dev/random or /dev/urandom&lt;BR /&gt;&lt;BR /&gt;a lsdev -e 57 shows&lt;BR /&gt;&lt;BR /&gt;    Character     Block       Driver          Class&lt;BR /&gt;       57           1         dmp             vxvm&lt;BR /&gt;&lt;BR /&gt;Also no startup scripts in the package. Any idea how to get the /dev/random devices?&lt;BR /&gt;</description>
      <pubDate>Thu, 13 Mar 2003 09:10:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898684#M748328</guid>
      <dc:creator>P.H. Vogt</dc:creator>
      <dc:date>2003-03-13T09:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: /dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898685#M748329</link>
      <description>We've just installed egd.pl on 11.00, and with little changes to the software, that almost works as /dev/random&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://sourceforge.net/projects/egd/" target="_blank"&gt;http://sourceforge.net/projects/egd/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Enjoy, have FUN! H.Merijn</description>
      <pubDate>Thu, 13 Mar 2003 09:27:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898685#M748329</guid>
      <dc:creator>H.Merijn Brand (procura</dc:creator>
      <dc:date>2003-03-13T09:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: /dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898686#M748330</link>
      <description>Is it possible to force OpenSSH binary distribution from software.hp.com to use /dev/random ?&lt;BR /&gt;&lt;BR /&gt;Michal</description>
      <pubDate>Thu, 13 Mar 2003 11:43:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898686#M748330</guid>
      <dc:creator>Mr Gorski</dc:creator>
      <dc:date>2003-03-13T11:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: /dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898687#M748331</link>
      <description>Chris: your paper looks great, but what I still don't understand is the exact relationship between openssh, openssl, and the entropy source.&lt;BR /&gt;&lt;BR /&gt;Your paper says: "For HP-SSH to utilize the new RNG no configuration changes need to be made to SSH."  That doesn't sound right to me.  Openssh's configure script attempts to find your entropy sources, and if it cannot find one, it uses its own fallback internal source.  Getting openssh to recognize a new source of entropy, like a newly created /dev/urandom, will require a rebuild, unless I'm missing something.&lt;BR /&gt;&lt;BR /&gt;[...tim spends hour playing with this stuff...]&lt;BR /&gt;&lt;BR /&gt;OK, here's what I think happens.  Openssl will detect and use a newly created /dev/[u]random at run time, even if that entropy source didn't exist at build time.  But Openssh decides whether or not to use its internal entropy source at build time.&lt;BR /&gt;&lt;BR /&gt;So for example, I had PRNGD running when I built openssl (0.9.6g), and then openssh (3.5p1).  Now I stop prngd, and remove its socket.  Openssh now stops functioning (i.e., the client dies with "Entropy collection failed" message).  I then create HP's new /dev/[u]random devices, and -- whamo! -- openssh starts working again.&lt;BR /&gt;&lt;BR /&gt;I suspect this is because openssh was built to use openssl's entropy, and openssl is smart enough to find the new device at run time.  But if openssh was built to use its own entropy source, it will never find /dev/[u]random without a rebuild.&lt;BR /&gt;&lt;BR /&gt;So the question for HP is, what entropy source does HP's SSH product use?  My guess is that they'll have to ship a new product to make use of the new /dev/[u]random devices.&lt;BR /&gt;&lt;BR /&gt;-Tim</description>
      <pubDate>Thu, 13 Mar 2003 15:57:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898687#M748331</guid>
      <dc:creator>Tim Maletic</dc:creator>
      <dc:date>2003-03-13T15:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: /dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898688#M748332</link>
      <description>Hi Tim,&lt;BR /&gt;&lt;BR /&gt;By default, I believe HP uses the ~openssh2/etc/ssh_prng_cmds file for it's source.&lt;BR /&gt;It's just a list of commands and bit rates to generate the entropy.&lt;BR /&gt;&lt;BR /&gt;HTH,&lt;BR /&gt;Jeff</description>
      <pubDate>Thu, 13 Mar 2003 16:07:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898688#M748332</guid>
      <dc:creator>Jeff Schussele</dc:creator>
      <dc:date>2003-03-13T16:07:01Z</dc:date>
    </item>
    <item>
      <title>Re: /dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898689#M748333</link>
      <description>Once you install /dev/random, HP-SSH will start using it without making any changes.  Check to make sure it is loaded:&lt;BR /&gt;&lt;BR /&gt;# kmadmin -s&lt;BR /&gt;Name            ID      Status          Type&lt;BR /&gt;=====================================================&lt;BR /&gt;krm             1       LOADED          WSIO&lt;BR /&gt;rng             2       LOADED          WSIO&lt;BR /&gt;# &lt;BR /&gt;If it's not loading, check /etc/rc.config.d/kminit and SAM/Kernel/Drivers and make sure rng is listed as a loadable module.</description>
      <pubDate>Thu, 13 Mar 2003 16:46:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898689#M748333</guid>
      <dc:creator>Chris Wong</dc:creator>
      <dc:date>2003-03-13T16:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: /dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898690#M748334</link>
      <description>It should be noted that /dev/random is ONLY supported on 11i &amp;amp; higher.&lt;BR /&gt;It's not supported on 11.0 &amp;amp; lower.&lt;BR /&gt;&lt;BR /&gt;My $0.02,&lt;BR /&gt;Jeff</description>
      <pubDate>Thu, 13 Mar 2003 17:32:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898690#M748334</guid>
      <dc:creator>Jeff Schussele</dc:creator>
      <dc:date>2003-03-13T17:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: /dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898691#M748335</link>
      <description>That link is dead to me, but I'd like to read your paper.  Can you email it to me: cvail "at" ercot dot com?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Chris</description>
      <pubDate>Thu, 13 Mar 2003 17:50:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898691#M748335</guid>
      <dc:creator>Chris Vail</dc:creator>
      <dc:date>2003-03-13T17:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: /dev/random &amp; SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898692#M748336</link>
      <description>Tim,&lt;BR /&gt;I think you can figure out the entropy issue by looking at the files in:&lt;BR /&gt;&lt;BR /&gt;/opt/ssh/src/ssh&lt;BR /&gt;&lt;BR /&gt;According to the SSH O'Reilly book:  SSH1 and SSH2 use a kernel-based randomness source if it is available, etc....&lt;BR /&gt;&lt;BR /&gt;I think you only need to recompile if you wanted to use an add-on "randomness source", such as EGD, which is what you would need to do with 11.0.&lt;BR /&gt;&lt;BR /&gt;- Chris</description>
      <pubDate>Thu, 13 Mar 2003 18:01:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dev-random-amp-ssh/m-p/2898692#M748336</guid>
      <dc:creator>Chris Wong</dc:creator>
      <dc:date>2003-03-13T18:01:53Z</dc:date>
    </item>
  </channel>
</rss>

