[SERVER-21253] Improve structure and functionality of random number generation classes Created: 02/Nov/15  Updated: 06/Dec/22

Status: Backlog
Project: Core Server
Component/s: Internal Code, Security
Affects Version/s: None
Fix Version/s: None

Type: Improvement Priority: Major - P3
Reporter: Spencer Jackson Assignee: Backlog - Security Team
Resolution: Unresolved Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Issue Links:
Related
is related to SERVER-9058 Use FIPS-140-2 Approved Pseudorandom ... Backlog
is related to SERVER-20919 Use OpenSSL to generate IVs Closed
Assigned Teams:
Server Security
Backwards Compatibility: Fully Compatible
Participants:

 Description   

Work on SERVER-20919 suggested some improvements that could improve our random number generation infrastructure across the codebase.

The following points are some suggested improvements:
1) We should have a way to access OpenSSL's CSPRNG
2) We should have a way to obtain arbitrary byte arrays full of random values
3) We should have a templated method to produce random numbers of requested types


Generated at Thu Feb 08 03:56:47 UTC 2024 using Jira 9.7.1#970001-sha1:2222b88b221c4928ef0de3161136cc90c8356a66.