Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 14 Jun 2013 15:14:00 +0200
From:      VANHULLEBUS Yvan <vanhu@FreeBSD.org>
To:        Slawa Olhovchenkov <slw@zxy.spb.ru>
Cc:        freebsd-net@freebsd.org
Subject:   Re: IPSec improvement
Message-ID:  <20130614131400.GA23375@zeninc.net>
In-Reply-To: <20130614103615.GQ34554@zxy.spb.ru>
References:  <20130614103615.GQ34554@zxy.spb.ru>

next in thread | previous in thread | raw e-mail | index | archive | help
Hi.

On Fri, Jun 14, 2013 at 02:36:15PM +0400, Slawa Olhovchenkov wrote:
> I am plan to do some improve in IPSec stack:
> 
> - AES-GCM support (from OpenBSD)

Dylan Castine already started to work on that last year (see ML's
archives), and we took some time to work together on that.

Unfortunately, patch hasn't been commited since, as Dylan needed some
more time to do some important cleanups on the code.

I'll try to recontact Dylan to see if he could take time to finish
that.


> - GOST 28147-89 and 34.10-2001 support (by modules)
> - support for IPSec acceleration in network cards

What kind of acceleration, in which kind of network card ?

Are you talking about encryption/authentication done in the network
card (or CPUs, or .....), or do you want to use advanced IPsec
offloading provided by some chipsets ?


Yvan.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20130614131400.GA23375>