You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Linux虚拟机上Bouncy Castle FIPS密钥对生成卡顿问题求助

Bouncy Castle FIPS RSA密钥对生成在Linux虚拟机卡顿,熵值不足且sysctl调整失败

我基于Bouncy Castle FIPS实现了证书生成功能,在物理Linux环境运行完全正常,但在Linux虚拟机中执行密钥对生成时会出现严重卡顿。

我的密钥对生成代码如下:

public static KeyPair generateKeyPair() throws GeneralSecurityException { 
    KeyPairGenerator keyPair = KeyPairGenerator.getInstance("RSA", "BCFIPS"); 
    keyPair.initialize(2048, new SecureRandom()); 
    return keyPair.generateKeyPair(); 
}

我尝试过以下排查和解决步骤,但均未解决问题:

  • 查找过类似问题的讨论,尝试了其中的方案但无效。
  • 检查发现系统初始熵值为1700(按要求应在3000-4000之间),按照方案调整后熵值提升到2600,但仍未达到要求的4000以上,卡顿问题依旧存在。
  • 尝试通过修改sysctl参数调整熵值阈值,在配置文件中添加:
    kernel.random.read_wakeup_threshold = 4096
    kernel.random.write_wakeup_threshold = 6144
    
    执行sysctl -p时出现错误:

    sysctl: setting key "kernel.random.read_wakeup_threshold": Invalid argument
    kernel.random.read_wakeup_threshold = 4096
    sysctl: setting key "kernel.random.write_wakeup_threshold": Invalid argument
    kernel.random.write_wakeup_threshold = 6144

  • 尝试安装haveged,执行yum install haveged提示包已安装,且haveged的FIPS检测结果正常:
    rngtest: starting FIPS tests...
    rngtest: bits received from input: 20000032
    rngtest: FIPS 140-2 successes: 1000
    rngtest: FIPS 140-2 failures: 0
    rngtest: FIPS 140-2(2001-10-10) Monobit: 0
    rngtest: FIPS 140-2(2001-10-10) Poker: 0
    rngtest: FIPS 140-2(2001-10-10) Runs: 0
    rngtest: FIPS 140-2(2001-10-10) Long run: 0
    rngtest: FIPS 140-2(2001-10-10) Continuous run: 0
    rngtest: input channel speed: (min=1.977; avg=13.431; max=23.782)Mibits/s
    rngtest: FIPS tests speed: (min=116.302; avg=143.533; max=147.856)Mibits/s
    rngtest: Program run time: 1561023 microseconds
    

想请教各位,还有什么方法可以解决虚拟机中Bouncy Castle FIPS生成RSA密钥对卡顿的问题?

内容的提问来源于stack exchange,提问作者ritesh kumar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 09:55:31