RB with random IV value for encryption

Shivanand.Kunijadar at toshiba-tsip.com Shivanand.Kunijadar at toshiba-tsip.com
Mon Dec 23 11:06:29 UTC 2024


Hi RB-Team,
We are facing reproducibility issues with encrypted images. We use a random IV for encryption with AES CBC. The resulting artifact is not reproducible due to the random IV used.

Based on information from the RB website, the Random data will make builds unreproducible and must be avoided[1].
>From a security perspective, it will be risky to use predictable IV values for the encryption.

Is there any other discussions related to the same in the mailing list or any guidelines related to handling random IV values for RB?

[1] https://reproducible-builds.org/docs/randomness/

Thanks & Regards
Shivanand K
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.reproducible-builds.org/pipermail/rb-general/attachments/20241223/34e20098/attachment.htm>


More information about the rb-general mailing list