HomeFreeBSD

OpenSSL: Support for kernel TLS offload (KTLS)

Description

OpenSSL: Support for kernel TLS offload (KTLS)

This merges upstream patches from OpenSSL's master branch to add
KTLS infrastructure for TLS 1.0-1.3 including both RX and TX
offload and SSL_sendfile support on both Linux and FreeBSD.

Note that TLS 1.3 only supports TX offload.

A new WITH/WITHOUT_OPENSSL_KTLS determines if OpenSSL is built with
KTLS support. It defaults to enabled on amd64 and disabled on all
other architectures.

Reviewed by: jkim (earlier version)
Approved by: secteam
Obtained from: OpenSSL (patches from master)
MFC after: 1 week
Relnotes: yes
Sponsored by: Netflix
Differential Revision: https://reviews.freebsd.org/D28273

Details

Provenance
jhbAuthored on Jan 16 2021, 12:17 AM
Reviewer
jkim
Differential Revision
D28273: OpenSSL: Support for kernel TLS offload (KTLS).
Parents
rG9a0a48b12d3d: usr.sbin/pkg: Don't re-define roundup2
Branches
Unknown
Tags
Unknown