Linux虚拟机上Bouncy Castle FIPS密钥对生成卡顿问题求助
Bouncy Castle FIPS RSA密钥对生成在Linux虚拟机卡顿,熵值不足且sysctl调整失败
我基于Bouncy Castle FIPS实现了证书生成功能,在物理Linux环境运行完全正常,但在Linux虚拟机中执行密钥对生成时会出现严重卡顿。
我的密钥对生成代码如下:
public static KeyPair generateKeyPair() throws GeneralSecurityException { KeyPairGenerator keyPair = KeyPairGenerator.getInstance("RSA", "BCFIPS"); keyPair.initialize(2048, new SecureRandom()); return keyPair.generateKeyPair(); }
我尝试过以下排查和解决步骤,但均未解决问题:
- 查找过类似问题的讨论,尝试了其中的方案但无效。
- 检查发现系统初始熵值为1700(按要求应在3000-4000之间),按照方案调整后熵值提升到2600,但仍未达到要求的4000以上,卡顿问题依旧存在。
- 尝试通过修改sysctl参数调整熵值阈值,在配置文件中添加:
执行kernel.random.read_wakeup_threshold = 4096 kernel.random.write_wakeup_threshold = 6144sysctl -p时出现错误:sysctl: setting key "kernel.random.read_wakeup_threshold": Invalid argument
kernel.random.read_wakeup_threshold = 4096
sysctl: setting key "kernel.random.write_wakeup_threshold": Invalid argument
kernel.random.write_wakeup_threshold = 6144 - 尝试安装haveged,执行
yum install haveged提示包已安装,且haveged的FIPS检测结果正常:rngtest: starting FIPS tests... rngtest: bits received from input: 20000032 rngtest: FIPS 140-2 successes: 1000 rngtest: FIPS 140-2 failures: 0 rngtest: FIPS 140-2(2001-10-10) Monobit: 0 rngtest: FIPS 140-2(2001-10-10) Poker: 0 rngtest: FIPS 140-2(2001-10-10) Runs: 0 rngtest: FIPS 140-2(2001-10-10) Long run: 0 rngtest: FIPS 140-2(2001-10-10) Continuous run: 0 rngtest: input channel speed: (min=1.977; avg=13.431; max=23.782)Mibits/s rngtest: FIPS tests speed: (min=116.302; avg=143.533; max=147.856)Mibits/s rngtest: Program run time: 1561023 microseconds
想请教各位,还有什么方法可以解决虚拟机中Bouncy Castle FIPS生成RSA密钥对卡顿的问题?
内容的提问来源于stack exchange,提问作者ritesh kumar
相关产品推荐
相关产品推荐

