With these instructions you'll always get a "good"[1] seed for your CSPRNG, and that includes virtual machines and clones.
[1] Of course that depends on how much you trust Intel. Don't ask the crypto mailing lists whether this is a good idea :-)
With these instructions you'll always get a "good"[1] seed for your CSPRNG, and that includes virtual machines and clones.
[1] Of course that depends on how much you trust Intel. Don't ask the crypto mailing lists whether this is a good idea :-)
"Create a new function, get_random_bytes_arch() which will use the architecture-specific hardware random number generator if it is present. Change get_random_bytes() to not use the HW RNG, even if it is avaiable.
...
So it's much better to use the HW RNG to improve the existing random number generator, by mixing in any entropy returned by the HW RNG into /dev/random's entropy pool, but to always _use_ /dev/random's entropy pool."
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.g...
Intels instructions perform the same as a HWRNG only it's built in to every chipset >= Ivy bridge. I actually think Linux's rng-tools incorporates it as a mix automatically.