Ubuntu Cloud PRNG seed
wiki.ubuntu.com
wiki.ubuntu.com
* man page: http://manpages.ubuntu.com/manpages/trusty/man1/pollinate.1....
* Q&A style blog post: http://blog.dustinkirkland.com/2014/02/random-seeds-in-ubunt...
* A "why this is scary" blog post: https://tim.siosm.fr/blog/2014/04/25/why-not-ubuntu-14.04-lt...
>"Starting with Ubuntu 14.04 LTS, Ubuntu cloud images include the Pollinate client, which will try to seed the PRNG with input from https://entropy.ubuntu.com for up to 3 seconds on first boot."
So, let me get this straight. An Ubuntu cloud image doesn't have enough entropy to create strong crypto keys on first boot (SSH, SSL, etc.). So, it connects over the Internet, via HTTPS, which requires strong crypto keys to make the connection, to gather its entropy. Facepalm.
The correct answer to generating enough entropy on boot is to either install haveged(8) as part of the imaging process, or to have the cloud image attach to a HWRNG using something similar to VirtIORNG.
Enough entropy needs to be created before making an HTTPS connection, not after.
I think that the real answer has to be blocking boot until enough entropy has been gathered, based on CPU or storage timing, or on console input.