URGENT: RNG broken for last 4 months

John-Mark Gurney jmg at funkthat.com
Tue Feb 17 18:02:27 UTC 2015


John-Mark Gurney wrote this message on Tue, Feb 17, 2015 at 09:37 -0800:
> If you are running a current kernel r273872 or later, please upgrade
> your kernel to r278907 or later immediately and regenerate keys.
> 
> I discovered an issue where the new framework code was not calling
> randomdev_init_reader, which means that read_random(9) was not returning
> good random data.  read_random(9) is used by arc4random(9) which is
> the primary method that arc4random(3) is seeded from.
> 
> This means most/all keys generated may be predictable and must be
> regenerated.  This includes, but not limited to, ssh keys and keys
> generated by openssl.  This is purely a kernel issue, and a simple
> kernel upgrade w/ the patch is sufficient to fix the issue.

It was brought to my attention (thanks Juli) that it might not be
clear that this issue does not effect any released version of FreeBSD.
It only effects people who run -current.

-- 
  John-Mark Gurney				Voice: +1 415 225 5579

     "All that I will do, has been done, All that I have, has not."


More information about the freebsd-current mailing list