RFE: Portable OpenSSH

Dan Kaminsky dankamin at cisco.com
Wed Mar 28 11:28:22 EST 2001


> when you're doing recompiling, a kill -HUP will reload the new binary
> with /dev/random support.

I want to add /dev/random support and have it just work without having to
recompile SSH.

> If you want to make entropy source configurable at runtime, why don't
> you supply the patches?

Going to.  Been working on authcommand and dynamic
forwarding(nuhh...new...channel...type...).

I've done the "complainer who refuses to code" bit before; learned from it.
:-)

> I don't like prngd.  It's a graceful hack to work around missing kernel
> features that every modern operating system should have.  The sooner
> I never have to run PRNGd on any of my systems, the happier I'll be.

SSH is a graceful hack.  Never forget that.

> On the other hand, telling Damien how he should support /dev/random
> vs prngd without supplying code to do what you seem to want it to
> do (if you want it so bad, why haven't you already written it
> yourself for your local systems) isn't reasonable.

You win :-)

--Dan





More information about the openssh-unix-dev mailing list