From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.saout.de ([127.0.0.1]) by localhost (mail.saout.de [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ch9dKJRlCu4w for ; Thu, 12 Jan 2012 17:28:17 +0100 (CET) Received: from v4.tansi.org (ns.km33513-03.keymachine.de [87.118.94.3]) by mail.saout.de (Postfix) with ESMTP for ; Thu, 12 Jan 2012 17:28:17 +0100 (CET) Received: from gatewagner.dyndns.org (84-74-163-71.dclient.hispeed.ch [84.74.163.71]) by v4.tansi.org (Postfix) with ESMTPA id 1B35F20471A for ; Thu, 12 Jan 2012 17:28:17 +0100 (CET) Date: Thu, 12 Jan 2012 17:28:15 +0100 From: Arno Wagner Message-ID: <20120112162815.GA13265@tansi.org> References: <20120112150640.GA1918@fancy-poultry.org> <4F0EFAD3.3090908@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <4F0EFAD3.3090908@redhat.com> Subject: Re: [dm-crypt] Twofish 3-way List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: dm-crypt@saout.de Do I understand this right that this can only work if you have independent disk accesses? For a single sector, the mode would prevent any paralellization (unless you set ECB, which is definitely not a good idea). Arno On Thu, Jan 12, 2012 at 04:22:59PM +0100, Milan Broz wrote: > On 01/12/2012 04:06 PM, Heinz Diehl wrote: > >Hi, > > > >since kernel 3.2 there is a new parallelized variant of twofish > >available via > > > >CONFIG_CRYPTO_TWOFISH_X86_64_3WAY > > > >How can I use it with LUKS/dmcrypt? My current config contains the > >following: > > > ># CONFIG_CRYPTO_TWOFISH is not set > >CONFIG_CRYPTO_TWOFISH_COMMON=y > >CONFIG_CRYPTO_TWOFISH_X86_64=y > >CONFIG_CRYPTO_TWOFISH_X86_64_3WAY=y > > > >How should these options be set up properly? > > You cannot set directly which version is used through dmcrypt interface, > (without patching kernel source) but cryptoAPI should detect the fastest > algorithm automatically. > > For separate modules, force load just that module and unload all other > should perhaps work as well (before crypto device activation). > > (see /proc/crypto and lsmod modules reference count to check which one > is really used) > > Milan > _______________________________________________ > dm-crypt mailing list > dm-crypt@saout.de > http://www.saout.de/mailman/listinfo/dm-crypt > -- Arno Wagner, Dr. sc. techn., Dipl. Inform., CISSP -- Email: arno@wagner.name GnuPG: ID: 1E25338F FP: 0C30 5782 9D93 F785 E79C 0296 797F 6B50 1E25 338F ---- One of the painful things about our time is that those who feel certainty are stupid, and those with any imagination and understanding are filled with doubt and indecision. -- Bertrand Russell