Page MenuHomeFreeBSD

ktls: Always create a software backend for receive sessions.
ClosedPublic

Authored by jhb on Oct 19 2021, 5:51 PM.
Tags
None
Referenced Files
F142076959: D32566.id97245.diff
Thu, Jan 15, 7:49 PM
Unknown Object (File)
Wed, Jan 7, 9:04 PM
Unknown Object (File)
Tue, Jan 6, 7:03 AM
Unknown Object (File)
Tue, Dec 30, 8:09 AM
Unknown Object (File)
Dec 10 2025, 7:22 PM
Unknown Object (File)
Nov 25 2025, 11:21 AM
Unknown Object (File)
Nov 14 2025, 1:07 AM
Unknown Object (File)
Nov 13 2025, 5:04 AM
Subscribers

Details

Summary

A future change to TOE TLS will require a software fallback for the
first few TLS records received. Future support for NIC TLS on receive
will also require a software fallback for certain cases.

Sponsored by: Chelsio Communications

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Passed
Unit
No Test Coverage
Build Status
Buildable 42260
Build 39148: arc lint + arc unit

Event Timeline

jhb requested review of this revision.Oct 19 2021, 5:51 PM

FYI, this effectively disables support for AES-CBC ciphers via TOE TLS. In the future I may add it back by adding a software decryption for MTE, but probably restrict it by default to only being enabled for TOE where the software route is only used for a few records.

This revision is now accepted and ready to land.Oct 19 2021, 10:19 PM