From owner-freebsd-security Sun Jun 24 12: 8:14 2001 Delivered-To: freebsd-security@freebsd.org Received: from obsecurity.dyndns.org (adsl-63-207-60-13.dsl.lsan03.pacbell.net [63.207.60.13]) by hub.freebsd.org (Postfix) with ESMTP id 1319F37B401; Sun, 24 Jun 2001 12:08:08 -0700 (PDT) (envelope-from kris@obsecurity.org) Received: by obsecurity.dyndns.org (Postfix, from userid 1000) id F293A66BF7; Sun, 24 Jun 2001 12:08:05 -0700 (PDT) Date: Sun, 24 Jun 2001 12:08:05 -0700 From: Kris Kennaway To: Dag-Erling Smorgrav Cc: "Karsten W. Rohrbach" , Soren Kristensen , hackers@FreeBSD.ORG, freebsd-security@FreeBSD.ORG Subject: Re: Status of encryption hardware support in FreeBSD Message-ID: <20010624120805.A67128@xor.obsecurity.org> References: <3B33A891.EC712701@soekris.com> <20010624181007.C52432@mail.webmonster.de> <20010624183147.F52432@mail.webmonster.de> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="2fHTh5uZTiUOsy+g" Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: ; from des@ofug.org on Sun, Jun 24, 2001 at 06:38:31PM +0200 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org --2fHTh5uZTiUOsy+g Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Sun, Jun 24, 2001 at 06:38:31PM +0200, Dag-Erling Smorgrav wrote: > "Karsten W. Rohrbach" writes: > > yup, exactly. to me it seems to be a major problem to get some unified > > api out of openssl adressing fucnctions on the hardware -- i simply do > > not know how other crypto chipsets do it, i just investigated the > > rainbow board. they got a patch against openssl 0.9.5 i think, that > > glues in the driver calls instead of standard lib functions. >=20 > Can you dig out this patch for me? It would be a big win if the > userland interface to Soren's hardware were compatible with Rainbow's > driver. I believe there is support in OpenSSL for this now (though not in the version we currently have imported; it's the OpenSSL-engine branch which supports hardware offload). Once there's a point to do so (e.g. whatever relevant kernel support), I can import this into FreeBSD. Kris --2fHTh5uZTiUOsy+g Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (FreeBSD) Comment: For info see http://www.gnupg.org iD8DBQE7NjqUWry0BWjoQKURAg+fAJ4iaUF0+6iPxnB/HtTkX5sHVnH1cgCggmiu t0KU2V7aB9tszwdu7tHmj8g= =xAkK -----END PGP SIGNATURE----- --2fHTh5uZTiUOsy+g-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message