[30897] in bugtraq
ssh host key generation in Red Hat Linux
daemon@ATHENA.MIT.EDU (Kent Borg)
Fri Jul 25 14:21:45 2003
Date: Fri, 25 Jul 2003 11:47:13 -0400
From: Kent Borg <kentborg@borg.org>
To: bugtraq@securityfocus.com
Message-ID: <20030725114713.F29161@borg.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
I recently installed Red Hat Linux 9 and noticed on the first boot a
message about generating ssh host keys. Isn't that a dangerous thing
to do on the first boot? Where is the installation going to get
enough good entropy so early in its life?
Maybe the paranoid thing to do is, as part of configuring a machine,
to regenerate those keys once user interaction (or other entropy
source) has had time to really stir the Linux entropy pool.
-kb