On Tue, Mar 19, 2013 at 18:09, Ted Unangst wrote:
> On Tue, Mar 19, 2013 at 18:17, matteo filippetto wrote:
>> Hi,
>>
>> what do you think about starting sshd before mount NFS resources?
> 
> ssh comes last because users are not allowed onto the system until the
> system is ready.

oh, and if there were any doubts about what it means for the system to
be ready...

https://www.usenix.org/conference/usenixsecurity12/mining-your-ps-and-qs-detection-widespread-weak-keys-embedded-devices

key quote:

"Although Ubuntu
tries to restore entropy saved during the last shutdown,
this happens slightly after the point when sshd first reads
from urandom. With no entropic inputs, urandom produces
a deterministic output stream."

oops.

Reply via email to