Re: random-device purpose in DNSSEC

2012-05-13 Thread Doug Barton
On 5/13/2012 2:11 PM, Alexander Gurvitz wrote: > My personal conclusions are that as I'll be using RSA only, > I don't need to worry about named.conf random device. That's not accurate. BIND uses random bits for other things as well. A decent source of entropy for /dev/random is a requirement for

Re: random-device purpose in DNSSEC

2012-05-13 Thread Alexander Gurvitz
On Fri, May 11, 2012 at 12:57 AM, Mark Andrews wrote: > > > > What random device used for ? > > ... I don't get why signing a zone requires any randomness. > > It doesn't for RSA.  However DSA does require randomness. > >  > Does BIND really needs that entropy, and how much ? > > Yes, if you are u