Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 20 Jan 2021 12:21:15 -0800
From:      Neel Chauhan <nc@freebsd.org>
To:        freebsd-current@freebsd.org
Subject:   Can In-Kernel TLS (kTLS) work with any OpenSSL Application?
Message-ID:  <bd56c9d3711738d65a074d73c04addd2@freebsd.org>

next in thread | raw e-mail | index | archive | help
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)

--=_938932f26e3bde6087a5ec59cc437c39
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset=US-ASCII;
 format=flowed

Hi freebsd-current@,

I know that In-Kernel TLS was merged into the FreeBSD HEAD tree a while 
back.

With 13.0-RELEASE around the corner, I'm thinking about upgrading my 
home server, well if I can accelerate any SSL application.

I'm asking because I have a home server on a symmetrical Gigabit 
connection (Google Fiber/Webpass), and that server runs a Tor relay. If 
you're interested in how Tor works, the EFF has a writeup: 
https://www.eff.org/pages/what-tor-relay

But the main point for you all is: more-or-less Tor relays deal with 
1000s TLS connections going into and out of the server.

Would In-Kernel TLS help with an application like Tor (or even load 
balancers/TLS termination), or is it more for things like web servers 
sending static files via sendfile() (e.g. CDN used by Netflix).

My server could also work with Intel's QuickAssist (since it has an 
Intel Xeon "Scalable" CPU). Would QuickAssist SSL be more helpful here?

I'm asking since I don't know whether to upgrade my home server to 13.x 
or leave it at 12.x. Yes, I do know we need a special OpenSSL to use 
kTLS.

-Neel

--=_938932f26e3bde6087a5ec59cc437c39
Content-Type: application/pgp-signature;
 name=signature.asc
Content-Disposition: attachment;
 filename=signature.asc;
 size=488
Content-Description: OpenPGP digital signature

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEFpeUj+sDItoNIly9vzSRBRPfYX0FAmAIkLsACgkQvzSRBRPf
YX32lQgAmubLcb2ZwNDhct9DyQyPlfEzKNdWZeM0tmO8js/CgxGz8OmRSWxUYTP3
INsihSVd1TBHGsYqHwFR0jMYB4yy26rlGZO+F7jz8WsZN+R//MH3jE68CwNKMYPk
ww622KczuxLdSLrhek/Dyq927teOYJE9BKJMed6Rlhx0eMN9Ic7OZrbhgrPwdM9M
LbWusAP/4aLDtyTRE9ANjzsyoGH30K/SQoSTEihODLx3zd0sNo1NJVu70Vn53TWj
0/6XQr296mh7q5zA56bqkcuFqInlghF1OTIm7f82UR+tSZ2xpJWW7Yb/YwKvzcTH
X7zuKROAevTrMfXTnjO5lmFtB8B8Bg==
=/yZF
-----END PGP SIGNATURE-----

--=_938932f26e3bde6087a5ec59cc437c39--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bd56c9d3711738d65a074d73c04addd2>