[22307] in bugtraq
Re: qmail starttls patch does not seed the random number generator
daemon@ATHENA.MIT.EDU (D. J. Bernstein)
Sun Aug 19 14:26:36 2001
Date: 19 Aug 2001 17:29:58 -0000
Message-ID: <20010819172958.8248.qmail@cr.yp.to>
Mail-Followup-To: qmail@list.cr.yp.to, bugtraq@securityfocus.com
From: "D. J. Bernstein" <djb@cr.yp.to>
To: bugtraq@securityfocus.com
Cc: qmail@list.cr.yp.to
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Jack Lloyd writes:
> the fact that qmail doesn't seed the RNG is a serious error
Nonsense. There is no TLS RNG in qmail. The patch under discussion is
not part of qmail. I didn't write the patch. I haven't reviewed it. I
don't distribute it. I don't use it. I am not responsible for its bugs.
For the record: I have authorized _none_ of the third-party patches that
are available for my software. Most of those patches are garbage.
---Dan