Sun Crypto cards and compiling SSH

From: Eric Watson (ewatson@law.harvard.edu)
Date: Fri Jun 14 2002 - 12:36:18 EDT


Hardware: V880 with Sun Crypto Accelator 1000
O/S: Solaris 8.0202
Software: tcp wrappers 7.6, open ssl 0.9.6b, open ssh 3.2.3

We are bringing up a new V880 with a Sun encryption card. We installed the
software that came with the card. The software and the instructions in the
manual are geared towards encrypting iPlanet and the Apache 1.3.12 that
ships with Solaris.

We want to use the card for encrypting SSH and our own instance of Apache
1.3.19. As delivered, the card's software provides libraries and binaries
for iPlanet and Apache 1.3.12. We applied the patch (112438-01) that
creates /dev/random and /dev/urandom. We've also successfully compiled tcp
wrappers 7.6, and open ssl 0.9.6.b

Problem: When we try and configure open ssh 3.2.3, no matter what we do,
the output at the end of the configuration (haven't tried to make yet) notes
that ssh will use use internal ssl rather than /dev/random.

Does anyone have any idea of how to compile ssh so that it will use
/dev/random (meaning the Crypto 1000 card) for encryption?

Will summarize.

Eric

************************************
Eric P. Watson
Supervisor of System Administration
  Services
Harvard Law School 617-496-6518
************************************
_______________________________________________
sunmanagers mailing list
sunmanagers@sunmanagers.org
http://www.sunmanagers.org/mailman/listinfo/sunmanagers



This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 23:24:27 EDT