Friends don't let friends generate insecure keys. Headless raspi setups generate ssh keys on first boot with relatively little entropy.

Don't forget to `dd if=/dev/random of=$raspi_root_mountpoint/var/lib/systemd/random-seed bs=1 count=512` before the first boot.


You should (also) do:
modprobe bcm2835-rng
and then start the rngd daemon from the rng-tools package.
This will massively increase the entropy pool.

You probably want to make it so that that happens at every boot.

