[22307] in bugtraq

home help back first fref pref prev next nref lref last post

Re: qmail starttls patch does not seed the random number generator

daemon@ATHENA.MIT.EDU (D. J. Bernstein)
Sun Aug 19 14:26:36 2001

Date: 19 Aug 2001 17:29:58 -0000
Message-ID: <20010819172958.8248.qmail@cr.yp.to>
Mail-Followup-To: qmail@list.cr.yp.to, bugtraq@securityfocus.com
From: "D. J. Bernstein" <djb@cr.yp.to>
To: bugtraq@securityfocus.com
Cc: qmail@list.cr.yp.to
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

Jack Lloyd writes:
> the fact that qmail doesn't seed the RNG is a serious error

Nonsense. There is no TLS RNG in qmail. The patch under discussion is
not part of qmail. I didn't write the patch. I haven't reviewed it. I
don't distribute it. I don't use it. I am not responsible for its bugs.

For the record: I have authorized _none_ of the third-party patches that
are available for my software. Most of those patches are garbage.

---Dan

home help back first fref pref prev next nref lref last post