Subject: Re: rpc xid randomness
To: der Mouse <mouse@Rodents.Montreal.QC.CA>
From: None <itojun@iijlab.net>
List: tech-security
Date: 09/08/2003 07:23:04
>>> date ones are a problem if more that one has to be allocated in the
>>> same tick.
>> The obvious solution there is to use a counter that's initialized
>> from the clock at reboot time.  We can't reboot in less than a
>> tick...
>
>No, but if more than one xid per tick is needed over the long term, the
>xids will get ahead of the clock, and then on reboot it will start
>reusing xids that were used recently.

	and if you adjust time to backwards by date(1) you are hosed.

itojun