From owner-freebsd-current@freebsd.org Tue Jan 7 23:02:26 2020 Return-Path: Delivered-To: freebsd-current@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 0193D1F532C for ; Tue, 7 Jan 2020 23:02:26 +0000 (UTC) (envelope-from rmacklem@uoguelph.ca) Received: from CAN01-TO1-obe.outbound.protection.outlook.com (mail-eopbgr670081.outbound.protection.outlook.com [40.107.67.81]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "mail.protection.outlook.com", Issuer "GlobalSign Organization Validation CA - SHA256 - G3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 47snvh6fvTz3HQ4; Tue, 7 Jan 2020 23:02:24 +0000 (UTC) (envelope-from rmacklem@uoguelph.ca) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=EXLHBT0X4x+uPkI/g735OYFbEOpW2ByUMSeKtl4JvT9nu8WaFf6QlA1WUJ/aVT95z+c1jvzsHr6hJBIaXCYHmv20s+nHuGeUHKXyh2us9WIziD+3XB4QM4o12Ki8x8WZ0oXaPrnHM7HkeBYeV7IISbuj6OnU+bHSawUoAoofyq791Cey7u1BRLpPvRc9ToZZbofkQ6V4mqER6GNTMAQnse1vLf2O9GGrbiVBPrRvhjRK247u13srWpEQOFkIAHS0Ij90ZNtl2ag8itUhR5XB64QkEgQKkgQ5WSDitiWxSah79QrzIRRHzXzk34EvMo4yA9VIMBhg4Jv1+4Fd8d93zA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Fy1u6zXsyRmBXl6XYwnq6sJ4A78he8K/Wgjyu2gdvPU=; b=RKc2IXfVg+AQgndXiKumh0z8g12kHEOAPXkSWnGyMq4pXiKrWQUf821rWeH2jG2JF8vHkytk48G1pqxVwujbBdg0cunEnYTAOIq2a7sTbmanGc9i8mWDYzEPpSk9tBVVkwCGcr9E6rmi3FJwHZrT1S3r2WOMSL42UsrneUscqPfEkspmdxKuHy5Ps76Xs7Td3TCT/4VhJqKi4HKiWZGKdnX/s8Z/NrLtEDW9LYUxZRbXW50QDfWXMMXT7iVZQQAb6M4KTwbyyaqI5aQBfqiBL6xXblgxflZMlIsD7fPvrtiVrr0R8ezcHjumQUEVjsAC8w+BfUqcdgSpAoGDg1nr7Q== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=uoguelph.ca; dmarc=pass action=none header.from=uoguelph.ca; dkim=pass header.d=uoguelph.ca; arc=none Received: from YQBPR0101MB1427.CANPRD01.PROD.OUTLOOK.COM (52.132.69.153) by YQBPR0101MB1553.CANPRD01.PROD.OUTLOOK.COM (52.132.71.11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2602.11; Tue, 7 Jan 2020 23:02:23 +0000 Received: from YQBPR0101MB1427.CANPRD01.PROD.OUTLOOK.COM ([fe80::7512:8580:8d82:6c94]) by YQBPR0101MB1427.CANPRD01.PROD.OUTLOOK.COM ([fe80::7512:8580:8d82:6c94%6]) with mapi id 15.20.2602.016; Tue, 7 Jan 2020 23:02:23 +0000 From: Rick Macklem To: "freebsd-current@FreeBSD.org" Subject: how to use the ktls Thread-Topic: how to use the ktls Thread-Index: AQHVxa2HeRfmo36hWEyrGcMaBhE88A== Date: Tue, 7 Jan 2020 23:02:23 +0000 Message-ID: Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-ms-publictraffictype: Email x-ms-office365-filtering-correlation-id: c3231206-7f69-4707-8c11-08d793c5a7ef x-ms-traffictypediagnostic: YQBPR0101MB1553: x-microsoft-antispam-prvs: x-ms-oob-tlc-oobclassifiers: OLM:8882; x-forefront-prvs: 027578BB13 x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(366004)(136003)(346002)(396003)(376002)(39860400002)(51874003)(199004)(189003)(478600001)(86362001)(2906002)(7696005)(6916009)(6506007)(4744005)(8676002)(26005)(76116006)(55016002)(91956017)(66446008)(33656002)(71200400001)(4326008)(66556008)(66476007)(81156014)(8936002)(186003)(450100002)(66946007)(786003)(316002)(64756008)(5660300002)(9686003)(52536014)(81166006); DIR:OUT; SFP:1101; SCL:1; SRVR:YQBPR0101MB1553; H:YQBPR0101MB1427.CANPRD01.PROD.OUTLOOK.COM; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1; received-spf: None (protection.outlook.com: uoguelph.ca does not designate permitted sender hosts) x-ms-exchange-senderadcheck: 1 x-microsoft-antispam: BCL:0; x-microsoft-antispam-message-info: /j+nC74wayk0QjlfO9/STxVOJHLAug1WvP+exMO60fANl3pnWnpZMzyxPeRXPOJ0wCNIVPUVvE5KnzayO4zpIv9EkfYNn5Xnv2C8RXgo8W863GK0FDil/OBzbFbKPLIPwtP8VcHn5qqzN8VxiRmquakwJTAq0CLJxCyikOiotKsawcLCuamzUejjLJ/FukvRgGJNp2FFj/hGuA2ylGnKGt9uGDBkeljhKiK57A0y4iwn0v02wiSELNxS6LP0RuZV3+Gsr/H7gL5iZ1tlCGS19V8WxZwuGeznZXmy/s1QJjYFVzS0RFRRJ7G3I7yVRRHIKuBB83SM02h9dslySF6HR8bv8dMSaY/i4GgSvcG3UfkOrFA2rYoFe/KYAsQG5UdmRCVmgqmEEYQ25ZPU3Y+I4wQbJA2K5nUcj/pC00CN+bhp/NSczooJFBsOAP4zRN3/HncbWkNHFcVSOTm75c92/nfddjRrp9Q8IMXH9xKyKkARt17jKxoTM78IgtGabuCA x-ms-exchange-transport-forked: True Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-OriginatorOrg: uoguelph.ca X-MS-Exchange-CrossTenant-Network-Message-Id: c3231206-7f69-4707-8c11-08d793c5a7ef X-MS-Exchange-CrossTenant-originalarrivaltime: 07 Jan 2020 23:02:23.0559 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: be62a12b-2cad-49a1-a5fa-85f4f3156a7d X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: sbiWp25JA3/25TAPm5gz8zmlGQBALHxaI0dco0X3Mx0chh7sgLVH98nvr664BSbe9kyhpeG2jHG+oau3Q4m7yg== X-MS-Exchange-Transport-CrossTenantHeadersStamped: YQBPR0101MB1553 X-Rspamd-Queue-Id: 47snvh6fvTz3HQ4 X-Spamd-Bar: ---- Authentication-Results: mx1.freebsd.org; dkim=none; dmarc=none; spf=pass (mx1.freebsd.org: domain of rmacklem@uoguelph.ca designates 40.107.67.81 as permitted sender) smtp.mailfrom=rmacklem@uoguelph.ca X-Spamd-Result: default: False [-4.67 / 15.00]; TO_DN_EQ_ADDR_SOME(0.00)[]; NEURAL_HAM_MEDIUM(-1.00)[-1.000,0]; FROM_HAS_DN(0.00)[]; TO_DN_SOME(0.00)[]; R_SPF_ALLOW(-0.20)[+ip4:40.107.0.0/16]; TO_MATCH_ENVRCPT_ALL(0.00)[]; MIME_GOOD(-0.10)[text/plain]; RCVD_TLS_LAST(0.00)[]; DMARC_NA(0.00)[uoguelph.ca]; NEURAL_HAM_LONG(-1.00)[-1.000,0]; RCVD_COUNT_THREE(0.00)[3]; IP_SCORE(-1.37)[ipnet: 40.64.0.0/10(-3.84), asn: 8075(-2.98), country: US(-0.05)]; RCPT_COUNT_TWO(0.00)[2]; RCVD_IN_DNSWL_NONE(0.00)[81.67.107.40.list.dnswl.org : 127.0.3.0]; FROM_EQ_ENVFROM(0.00)[]; R_DKIM_NA(0.00)[]; MIME_TRACE(0.00)[0:+]; ASN(0.00)[asn:8075, ipnet:40.64.0.0/10, country:US]; ARC_ALLOW(-1.00)[i=1] X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 07 Jan 2020 23:02:26 -0000 Hi,=0A= =0A= Now that I've completed NFSv4.2 I'm on to the next project, which is making= NFS=0A= work over TLS.=0A= Of course, I know absolutely nothing about TLS, which will make this an int= eresting=0A= exercise for me.=0A= I did find simple server code in the OpenSSL doc. which at least gives me a= starting=0A= point for the initialization stuff.=0A= As I understand it, this initialization must be done in userspace?=0A= =0A= Then somehow, the ktls takes over and does the encryption of the=0A= data being sent on the socket via sosend_generic(). Does that sound right?= =0A= =0A= So, how does the kernel know the stuff that the initialization phase (hands= hake)=0A= figures out, or is it magic I don't have to worry about?=0A= =0A= Don't waste much time replying to this. A few quick hints will keep me goin= g for=0A= now. (From what I've seen sofar, this TLS stuff isn't simple. And I thought= Kerberos=0A= was a pain.;-)=0A= =0A= Thanks in advance for any hints, rick=0A=