Damien Miller | a8e06ce | 2003-11-21 23:48:55 +1100 | [diff] [blame] | 1 | .\" $Id: ssh-rand-helper.8,v 1.2 2003/11/21 12:48:56 djm Exp $ |
Damien Miller | 32e4818 | 2002-04-14 19:27:12 +1000 | [diff] [blame] | 2 | .\" |
| 3 | .\" Copyright (c) 2002 Damien Miller. All rights reserved. |
| 4 | .\" |
| 5 | .\" Redistribution and use in source and binary forms, with or without |
| 6 | .\" modification, are permitted provided that the following conditions |
| 7 | .\" are met: |
| 8 | .\" 1. Redistributions of source code must retain the above copyright |
| 9 | .\" notice, this list of conditions and the following disclaimer. |
| 10 | .\" 2. Redistributions in binary form must reproduce the above copyright |
| 11 | .\" notice, this list of conditions and the following disclaimer in the |
| 12 | .\" documentation and/or other materials provided with the distribution. |
| 13 | .\" |
| 14 | .\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR |
| 15 | .\" IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES |
| 16 | .\" OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. |
| 17 | .\" IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, |
| 18 | .\" INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT |
| 19 | .\" NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, |
| 20 | .\" DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY |
| 21 | .\" THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
| 22 | .\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF |
| 23 | .\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
| 24 | .\" |
| 25 | .Dd April 14, 2002 |
| 26 | .Dt SSH-RAND-HELPER 8 |
| 27 | .Os |
| 28 | .Sh NAME |
| 29 | .Nm ssh-rand-helper |
| 30 | .Nd Random number gatherer for OpenSSH |
| 31 | .Sh SYNOPSIS |
| 32 | .Nm ssh-rand-hlper |
| 33 | .Op Fl vxXh |
| 34 | .Op Fl b Ar bytes |
| 35 | .Sh DESCRIPTION |
| 36 | .Nm |
Damien Miller | a8e06ce | 2003-11-21 23:48:55 +1100 | [diff] [blame] | 37 | is a small helper program used by |
Damien Miller | 32e4818 | 2002-04-14 19:27:12 +1000 | [diff] [blame] | 38 | .Xr ssh 1 , |
| 39 | .Xr ssh-add 1 , |
| 40 | .Xr ssh-agent 1 , |
| 41 | .Xr ssh-keygen 1 , |
Damien Miller | a8e06ce | 2003-11-21 23:48:55 +1100 | [diff] [blame] | 42 | .Xr ssh-keyscan 1 |
Damien Miller | 32e4818 | 2002-04-14 19:27:12 +1000 | [diff] [blame] | 43 | and |
| 44 | .Xr sshd 8 |
Damien Miller | a8e06ce | 2003-11-21 23:48:55 +1100 | [diff] [blame] | 45 | to gather random numbers of cryptographic quality if the |
Damien Miller | 32e4818 | 2002-04-14 19:27:12 +1000 | [diff] [blame] | 46 | .Xr openssl 4 |
| 47 | library has not been configured to provide them itself. |
| 48 | .Pp |
Damien Miller | a8e06ce | 2003-11-21 23:48:55 +1100 | [diff] [blame] | 49 | Normally |
Damien Miller | 32e4818 | 2002-04-14 19:27:12 +1000 | [diff] [blame] | 50 | .Nm |
| 51 | will generate a strong random seed and provide it to the calling |
Damien Miller | a8e06ce | 2003-11-21 23:48:55 +1100 | [diff] [blame] | 52 | program via standard output. If standard output is a tty, |
Damien Miller | 32e4818 | 2002-04-14 19:27:12 +1000 | [diff] [blame] | 53 | .Nm |
| 54 | will instead print the seed in hexidecimal format unless told otherwise. |
| 55 | .Pp |
| 56 | .Nm |
| 57 | will by default gather random numbers from the system commands listed |
| 58 | in |
| 59 | .Pa /etc/ssh/ssh_prng_cmds . |
Damien Miller | a8e06ce | 2003-11-21 23:48:55 +1100 | [diff] [blame] | 60 | The output of each of the commands listed will be hashed and used to |
| 61 | generate a random seed for the calling program. |
Damien Miller | 32e4818 | 2002-04-14 19:27:12 +1000 | [diff] [blame] | 62 | .Nm |
Damien Miller | a8e06ce | 2003-11-21 23:48:55 +1100 | [diff] [blame] | 63 | will also store seed files in |
Damien Miller | 32e4818 | 2002-04-14 19:27:12 +1000 | [diff] [blame] | 64 | .Pa ~/.ssh/prng_seed |
| 65 | between executions. |
| 66 | .Pp |
Damien Miller | a8e06ce | 2003-11-21 23:48:55 +1100 | [diff] [blame] | 67 | Alternately, |
Damien Miller | 32e4818 | 2002-04-14 19:27:12 +1000 | [diff] [blame] | 68 | .Nm |
Damien Miller | a8e06ce | 2003-11-21 23:48:55 +1100 | [diff] [blame] | 69 | may be configured at build time to collect random numbers from a |
Damien Miller | 32e4818 | 2002-04-14 19:27:12 +1000 | [diff] [blame] | 70 | EGD/PRNGd server via a unix domain or localhost tcp socket. |
| 71 | .Pp |
Damien Miller | a8e06ce | 2003-11-21 23:48:55 +1100 | [diff] [blame] | 72 | This program is not intended to be run by the end-user, so the few |
Damien Miller | 32e4818 | 2002-04-14 19:27:12 +1000 | [diff] [blame] | 73 | commandline options are for debugging purposes only. |
| 74 | .Bl -tag -width Ds |
| 75 | .It Fl b Ar bytes |
| 76 | Specify the number of random bytes to include in the output. |
| 77 | .It Fl x |
| 78 | Output a hexidecimal instead of a binary seed. |
| 79 | .It Fl X |
| 80 | Force output of a binary seed, even if standard output is a tty |
| 81 | .It Fl v |
| 82 | Turn on debugging message. Multiple |
| 83 | .Fl v |
| 84 | options will increase the debugging level. |
| 85 | .Fl h |
| 86 | Display a summary of options. |
| 87 | .El |
| 88 | .Sh AUTHORS |
| 89 | Damien Miller <djm@mindrot.org> |
| 90 | .Sh SEE ALSO |
| 91 | .Xr ssh 1 , |
| 92 | .Xr ssh-add 1 , |
| 93 | .Xr ssh-keygen 1 , |
| 94 | .Xr sshd 8 |