#39498 [Bgs]: ext/mcrypt/mcrypt.c hardcoded to use /dev/random
| From: | derick@php.net | Date: | Mon, 13 Nov 2006 16:28:44 +0000 |
| Subject: | #39498 [Bgs]: ext/mcrypt/mcrypt.c hardcoded to use /dev/random | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-104915@lists.php.net to get a copy of this message | ||
ID: 39498
Updated by: derick@php.net
Reported By: mark at exonetric dot com
Status: Bogus
Bug Type: Performance problem
Operating System: Linux 2.6/Debian Etch
PHP Version: 4.4.4
New Comment:
http://no.php.net/mcrypt_create_iv
Previous Comments:
------------------------------------------------------------------------
[2006-11-13 15:58:15] tony2001@php.net
You can use MCRYPT_DEV_URANDOM and get the data for /dev/urandom.
------------------------------------------------------------------------
[2006-11-13 15:48:11] mark at exonetric dot com
Description:
------------
mcrypt.c appears to be written to use /dev/random for entropy in all
cases. As good entropy is a limited resource when obtained from
/dev/random, code that makes frequent calls to mcrypt routines that
require entropy can block waiting for entropy unexpectedly.
PHP_FUNCTION(mcrypt_create_iv) should be modified to permit
configuration of /dev/random or /dev/urandom at least at compile time
if not at run time.
Reproduce code:
---------------
any code that calls mcrypt routines frequently
Expected result:
----------------
if called frequently enough, will block waiting for entropy.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=39498&edit=1