
i've not digged through the whole openssl source yet - but it seems to me that 
the recent Debian
Issue with the ssleay_rand_add method here

does not affect the command line tool when called with

openssl req -config $MY_CONFIG -noout -x509 -newkey rsa:$MY_KEY_LENGTH
(in contrast to openssl genrsa)
where in $CONFIG *no* RANDFILE is defined.

AFAIK the method in question is never called from the request command line 
utility. And by default
- the /root/.rnd or $HOME/.rnd file is always used if no RANDFILE is given.

Anyone can answer this?


OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    openssl-users@openssl.org
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to