Hi,

> Botan do try to use e.g. /dev/random, /dev/srandom, /dev/urandom, 
> /var/run/egd-pool, /dev/egd-pool before trying the unix commands. (Botan 1.11 
> will do EGD after the unix commands)

Thanks for adding that.  I suppose that means that Botan does do its best, and 
it is not sane to try and improve it.

As far as I'm concerned that ends this discussion topic -- as it was centered 
around a fallback scenario that we should all be able to avoid easily.

> If we would add entropy sources directly in SoftHSM, I think would do similar 
> to how Botan is doing it. So it is much better to leave it to Botan. Just 
> that we verify the build flags.

I agree.

-Rick_______________________________________________
Opendnssec-user mailing list
[email protected]
https://lists.opendnssec.org/mailman/listinfo/opendnssec-user

Reply via email to