[$] FIPS-compliant random numbers for the kernel

Post Syndicated from original https://lwn.net/Articles/877607/rss

The Linux random-number generator (RNG) seems to attract an outsized amount
of attention
(and work) for what is, or seemingly should be, a fairly small
component of the kernel. In part that is because random numbers, and
their quality, are extremely important to a number of security
protections, from unpredictable IP-packet sequence numbers to cryptographic
keys. A recent post of
version 43 of the Linux Random Number
Generator (LRNG) by Stephan Müller is not likely to go any further than its
predecessors, but the discussion around it may lead to support for a
feature that some distributions need.