Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Introduce v2 of entropy standard #674

Open
mbuechse opened this issue Jul 31, 2024 · 4 comments
Open

Introduce v2 of entropy standard #674

mbuechse opened this issue Jul 31, 2024 · 4 comments
Assignees
Labels
SCS is standardized SCS is standardized
Milestone

Comments

@mbuechse
Copy link
Contributor

v1 says that rngd must be installed, but that is not sufficient. It must be installed and running. Therefore create v2.

@mbuechse
Copy link
Contributor Author

mbuechse commented Jul 31, 2024

We will have to see whether the test script also needs to be changed. If #668 comes to pass quickly enough, then the script won't need to be touched (other than what is done in #668 itself)

addendum since this topic isn't time critical, let's wait for #668 (except we need to finalize SCS-compatible IaaS v5 earlier).

@mbuechse
Copy link
Contributor Author

@artificial-intelligence I have to ask again: Do we really need this?

Con:

  • rngd is only needed in case you want to pipe in random numbers from an external rng
  • this is a fringe case, because random numbers in CPUs (even virtualized) are good these days
  • original OS images don't have pre-enabled rngd, so requiring it would involve a lot of effort on the CSP side that may have very little demand
  • finally, people can always create their own image with pre-enabled rngd (and if they want their external rng, they might want this amount of control anyway)

@mbuechse
Copy link
Contributor Author

@artificial-intelligence I have another question. Shall we relax the recommendations on image properties to only apply for images with visibility "public"? The image metadata check seems to only check those as well.

@mbuechse
Copy link
Contributor Author

@artificial-intelligence I've been told that images with visibility private cannot be controlled by the operator, so it's no use regulating those.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
SCS is standardized SCS is standardized
Projects
Status: Backlog
Development

No branches or pull requests

2 participants