Re: lack of boot-time entropy on arm64 ec2 instances
On Wed, Jan 08, 2020 at 12:50:04PM -0800, Ross Vandegrift wrote:
> I know of two other options:
> - pollinate
> - jitterentropy-rngd
>
> pollinate downloads seeds remotely, which feels wrong - and itself may
> require random numbers. I've never tried jitterentropy.
IMO these are roughly equivalent to haveged, in that they're userspace
accumulators of entropy that try to seed the kernel. I think I prefer
haveged's approach, but I'm really not qualified to judge.
Reply to: