• ITUGLIB Note: OpenSSL on L-series

    From Randall@rsbecker@nexbridge.com to comp.sys.tandem on Wed Sep 20 15:18:14 2023
    From Newsgroup: comp.sys.tandem

    Hi Everyone,
    Just something to note: If you are on OpenSSL 3.0.10 or higher, the PRNGD server is not required on L-series. In the 3.0.10 or higher builds, the x86 hardware randomizer is successfully used even if PRNGD is running or not running. The same for 3.1.2 or higher. When 3.2 comes out, it will also support the hardware randomizer.
    The advantage is that this is much faster when generating randomness, easier to configure, because you do not need PRNGD. Note that other subsystems *do* require PRNGD so do not just stop it and hope everything works. Contact your vendor for requirements. For ITUGLIB, git, OpenSSL, curl, rsync, should not need PRNGD following these versions. Let us know if you find something different. Ideally, open a case at https://github.com/openssl/openssl/issues indicating NonStop in the title of the issue and probably note @rsbeckerca in the text of the case so that I will get notified when the case opens. For all OpenSSL cases, make sure to attach the output from perl configdata.pm --dump if you have build OpenSSL yourself.
    Regards,
    Randall Becker
    On Behalf of the ITUGLIB Technical Committee.
    --- Synchronet 3.21d-Linux NewsLink 1.2