[exim-dev] [Bug 654] [GnuTLS] [patch] Use a random seed file…

Top Page
Delete this message
Reply to this message
Author: Marc Haber
Date:  
To: exim-dev
Subject: [exim-dev] [Bug 654] [GnuTLS] [patch] Use a random seed file to limit entropy usage
------- You are receiving this mail because: -------
You are on the CC list for the bug.

http://bugs.exim.org/show_bug.cgi?id=654




--- Comment #5 from Marc Haber <mh+exim-bugzilla@???> 2008-01-31 21:19:02 ---
I have tried the patch that Andreas committed to the Debian exim4 svn a few
days ago on my productive mail server.

http://svn.debian.org/wsvn/pkg-exim4/exim/trunk/debian/patches/65_saverandomseed.dpatch?op=file&rev=0&sc=0

Available entropy during typical use on this system increased from an average
200 to over 3000. Success.

However, the secondary MX (which delivers some spam to the primary MX) noted
that the primary box had become unreliable in TLS:

2008-01-30 14:51:21 1JKDKT-0003ME-AG Remote host mailgate.zugschlus.de
[85.214.68.41] closed connection in response to STARTTLS

When this happened (a couple of times per hour), I didn't get any atypical log
entries on mailgate.

This was a repeating, but intermittent failure since mailgate continued to work
normally, and STARTTLS was successful most of the time.

mailgate is Debian sarge, running an exam 4.69-2 backport linked against
libgnutls11 (1.4.4-3) and libcrypt11 (1.2.3-2).

Going back to the same exim sans the random-seed patch, entropy average went
back to 200, but the STARTTLS failures vanished.


--
Configure bugmail: http://bugs.exim.org/userprefs.cgi?tab=email