From owner-freebsd-security@FreeBSD.ORG Mon May 25 04:15:21 2015 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 16C4927D for ; Mon, 25 May 2015 04:15:21 +0000 (UTC) (envelope-from toasty@dragondata.com) Received: from mail-ig0-x235.google.com (mail-ig0-x235.google.com [IPv6:2607:f8b0:4001:c05::235]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id CE65295F for ; Mon, 25 May 2015 04:15:20 +0000 (UTC) (envelope-from toasty@dragondata.com) Received: by igbpi8 with SMTP id pi8so29728068igb.0 for ; Sun, 24 May 2015 21:15:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dragondata.com; s=google; h=content-type:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=kmoeNCbvmg0oza8bvybkRlpt18gDgLadueOhVzBclIc=; b=bGXQb0imNhIBz0EFRawBmyePeUi7aa1PQid0Up4ihGT56AstF2rbhlRtN5fc2WsTo3 RJKDnl2U3vtd26odPb99QB2+KzK6OuJnhy0FxtGP5YfecrJXB/6R4VKblgkEKqvK5qPc c61hFznua/K13eEQ4LtrAZGwQI+BmdsodHIMQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:content-type:mime-version:subject:from :in-reply-to:date:cc:content-transfer-encoding:message-id:references :to; bh=kmoeNCbvmg0oza8bvybkRlpt18gDgLadueOhVzBclIc=; b=XZHcDHcArRPbeRI3bPEm1Rg+dpB/hHTUwumCcDa2evMh7KHS8fBN9ljUaQTHJSBCw/ b3hs4L9MhvpW16XcqsXrsVxNtIT3j7mT//s30zMeasMIyJDLBvvTLwE/hj7yeeK/KOXn zQyBJHygHtxAN8mClUcYCqZUOBGuQyrDr+HRqdAOKiNMEYQB8UJL+xPDPIxMxI81BOAm qEGxX3Ozn0liA6Cscp71gpCecrpR6UxVbNYdE45BZg4obiU3JnZcI+tT1tO3mX9K1luk +1W8lcvt8E+DP63Pe2zlNRe1v/ra9ThPOt3pMT+T+m0QCmKcuPl9mVvL94FNaAmLL3km ArQQ== X-Gm-Message-State: ALoCoQkrfeRhXUVe9ZXQOYD1vhyBe4OatkjUlPveF725LKPVb+7wX0NjtL2Clx5I//hXBFtE4GkS X-Received: by 10.50.138.70 with SMTP id qo6mr20641611igb.15.1432527320097; Sun, 24 May 2015 21:15:20 -0700 (PDT) Received: from unassigned.v6.your.org ([2001:4978:1:45:4468:d71f:d52c:9235]) by mx.google.com with ESMTPSA id 17sm2214346ioq.39.2015.05.24.21.15.18 (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Sun, 24 May 2015 21:15:18 -0700 (PDT) Content-Type: text/plain; charset=utf-8 Mime-Version: 1.0 (Mac OS X Mail 8.2 \(2070.4\)) Subject: Re: Atom C2758 - loading aesni(4) reduces performance From: Kevin Day In-Reply-To: <20150524224454.GX37063@funkthat.com> Date: Sun, 24 May 2015 23:15:17 -0500 Cc: freebsd-security@freebsd.org Content-Transfer-Encoding: quoted-printable Message-Id: <687C0C52-08FA-4234-9A64-527163EED3C8@dragondata.com> References: <6BA42026-C785-40B5-B9CF-DD4280693C41@dragondata.com> <20150524224454.GX37063@funkthat.com> To: John-Mark Gurney X-Mailer: Apple Mail (2.2070.4) X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 25 May 2015 04:15:21 -0000 > On May 24, 2015, at 5:44 PM, John-Mark Gurney = wrote: >=20 > If you have cryptodev loaded, this is to be expected as OpenSSL will > use /dev/crypto instead of the AES-NI instructions.. Just don't load > cryptodev and you'll be fine.. >=20 So to make sure I=E2=80=99m understanding=E2=80=A6 openssl has native = AES-NI support, and it also can use /dev/crypto. It=E2=80=99s preferring = /dev/crypto, but /dev/crypto has much higher overhead? =E2=80=94 Kevin