Re: dnssec-keygen not responding

2011-12-01 Thread Jan-Piet Mens
On Wed Nov 30 2011 at 20:45:30 CET, Michael Graff wrote: For my VM environment, I bought a USB random source, and share it across the VMs with a little daemon I wrote. Would you be willing to give us a few more details, such as the name of the USB random source generator (is it an Entropy

Re: dnssec-keygen not responding

2011-12-01 Thread Hauke Lampe
Jan-Piet Mens wrote: - Original message - Would you be willing to give us a few more details, such as the name of the USB random source generator (is it an Entropy Key) ? Of course , if you do tell us what hardware you're using, the next thing will be we'll want a copy of your

Re: dnssec-keygen not responding

2011-12-01 Thread Michael Graff
I'm using an Araneus Alea I, from http://www.araneus.fi/products-alea-eng.html. I'm sure others would work as well. I know the creator of this device personally though, so it's the one sticking out of the back of the box I own. :) As for the daemon, well, I may have to find the time to

Re: dnssec-keygen not responding

2011-12-01 Thread Paul Wouters
On Thu, 1 Dec 2011, Michael Graff wrote: I'm using an Araneus Alea I, from http://www.araneus.fi/products-alea-eng.html. I'm sure others would work as well. I know the creator of this device personally though, so it's the one sticking out of the back of the box I own. :) At 150 EURO,

Re: dnssec-keygen not responding

2011-12-01 Thread Warren Kumari
Yeah, a number of motherboards now come with TPMs that include hardware RNGs... My current personal server (Dell R710) has just such a beastie -- there is some info here: http://domsch.com/blog/?p=107 and I *think* that the rng-tools package now supports it natively I spent *many* hours

Dell TPM, was Re: dnssec-keygen not responding

2011-12-01 Thread Paul Wouters
On Thu, 1 Dec 2011, Warren Kumari wrote: Yeah, a number of motherboards now come with TPMs that include hardware RNGs... My current personal server (Dell R710) has just such a beastie -- there is some info here: http://domsch.com/blog/?p=107 and I *think* that the rng-tools package now

Re: dnssec-keygen not responding

2011-11-30 Thread Adam Tkac
On Wed, Nov 30, 2011 at 12:18:04AM -0500, Alan Clegg wrote: On 11/30/2011 12:15 AM, vishesh kumar wrote: Hi All I am trying to generate keys for signing vishesh.com http://vishesh.com domain using following command (for testing purpose) dnssec-keygen -a RSASHA1 -b 768 -n ZONE

Re: dnssec-keygen not responding

2011-11-30 Thread Torsten Segner
Am Wed, 30 Nov 2011 09:40:44 +0100 schrieb Adam Tkac at...@redhat.com: On Wed, Nov 30, 2011 at 12:18:04AM -0500, Alan Clegg wrote: On 11/30/2011 12:15 AM, vishesh kumar wrote: Hi All I am trying to generate keys for signing vishesh.com http://vishesh.com domain using following

Re: dnssec-keygen not responding

2011-11-30 Thread Michael Graff
On Nov 30, 2011, at 3:01 AM, Torsten Segner wrote: In RHEL there is a RPM package called unuran. It's a random number generator daemon using either a piece of hardware or /dev/urandom as source. Running this will provide enough entropy to create lots of keys. I'd be rather wary of keys

Re: dnssec-keygen not responding

2011-11-30 Thread Mark Elkins
On Wed, 2011-11-30 at 13:45 -0600, Michael Graff wrote: On Nov 30, 2011, at 3:01 AM, Torsten Segner wrote: In RHEL there is a RPM package called unuran. It's a random number generator daemon using either a piece of hardware or /dev/urandom as source. Running this will provide enough

Re: dnssec-keygen not responding

2011-11-30 Thread Paul Wouters
On Wed, 30 Nov 2011, Michael Graff wrote: On Nov 30, 2011, at 3:01 AM, Torsten Segner wrote: In RHEL there is a RPM package called unuran. It's a random number generator daemon using either a piece of hardware or /dev/urandom as source. Running this will provide enough entropy to create lots

RE: dnssec-keygen not responding

2011-11-30 Thread Spain, Dr. Jeffry A.
I'd be rather wary of keys made from /dev/urandom but I am often times a paranoid security freak. Inexpensive USB-attachable RNG: http://www.entropykey.co.uk/ Jeffry A. Spain Network Administrator Cincinnati Country Day School ___ Please visit

Re: dnssec-keygen not responding

2011-11-29 Thread Alan Clegg
On 11/30/2011 12:15 AM, vishesh kumar wrote: Hi All I am trying to generate keys for signing vishesh.com http://vishesh.com domain using following command (for testing purpose) dnssec-keygen -a RSASHA1 -b 768 -n ZONE vishesh.com http://vishesh.com. But its not responding , i waited