On 02/19/2008 08:15 PM, Paul Querna wrote:
André Malo wrote:
* [EMAIL PROTECTED] wrote:

Author: pquerna
Date: Tue Feb 19 09:05:26 2008
New Revision: 629164

URL: http://svn.apache.org/viewvc?rev=629164&view=rev
Log:
Improve generation of the seed to rand, by using
apr_generate_random_bytes, rather than the current time as a seed.

Wouldn't it make more sense to drop all that seed and rand hassle and just use the apr-random bytes directly as salt (alphabet[byte % len(alphabet)])

I guess so....

apr-random though has this nasty habit of using really random sources, and using all entropy on a system, and I'd prefer to not use it more than needed..... As this has been the source of pain and several bug reports in the past....

True. Thats why I normally compile with --with-devrandom=/dev/urandom.
But this may not be suitable for all situations.
Maybe there should be a apr_generate_urandom_bytes. But this is a story
for the apr list.

Regards

Rüdiger

Reply via email to