From: Hannes Reinecke <hare@kernel.org>
To: Christoph Hellwig <hch@lst.de>
Cc: Sagi Grimberg <sagi@grimberg.me>, Keith Busch <kbusch@kernel.org>,
linux-nvme@lists.infradead.org, Hannes Reinecke <hare@kernel.org>
Subject: [PATCHv6 0/8] nvme: implement secure concatenation
Date: Thu, 18 Jul 2024 17:06:50 +0200 [thread overview]
Message-ID: <20240718150658.99580-1-hare@kernel.org> (raw)
Hi all,
here's my attempt to implement secure concatenation for NVMe-of TCP
as outlined in TP8018.
The original (v5) patchset had been split in two, and this is the
second part based on top of the patchset 'nvme: fixes for secure
concatenation' sent earlier to the mailinglist.
Secure concatenation means that a TLS PSK is generated from the key
material negotiated by the DH-HMAC-CHAP protocol, and the TLS PSK
is then used for a subsequent TLS connection.
The difference between the original definition of secure concatenation
and the method outlined in TP8018 is that with TP8018 the connection
is reset after DH-HMAC-CHAP negotiation, and a new connection is setup
with the generated TLS PSK.
To implement that Sagi came up with the idea to directly reset the
admin queue once the DH-CHAP negotiation has completed; that way
it will be transparent to the upper layers and we don't have to
worry about exposing queues which should not be used.
As usual, comments and reviews are welcome.
Patchset can be found at
git.kernel.org:/pub/scm/linux/kernel/git/hare/nvme.git
branch secure-concat.v6
Changes to v5:
- Include reviews from Sagi
- Split patchset in two parts
Changes to v4:
- Rework reset admin queue functionality based on an idea
from Sagi (thanks!)
- kbuild robot fixes
- Fixup dhchap negotiation with non-empty C2 value
Changes to v3:
- Include reviews from Sagi
- Do not start I/O queues after DH-HMAC-CHAP negotiation
- Use bool to indicate TLS has been enabled on a queue
- Add 'tls_keyring' sysfs attribute
- Add 'tls_configured_key' sysfs attribute
Changes to v2:
- Fixup reset after dhchap negotiation
- Disable namespace scanning on I/O queues after
dhchap negotiation
- Reworked TLS key handling (again)
Changes to the original submission:
- Sanitize TLS key handling
- Fixup modconfig compilation
Hannes Reinecke (8):
crypto,fs: Separate out hkdf_extract() and hkdf_expand()
nvme: add nvme_auth_generate_psk()
nvme: add nvme_auth_generate_digest()
nvme: add nvme_auth_derive_tls_psk()
nvme-keyring: add nvme_tls_psk_refresh()
nvme-tcp: request secure channel concatenation
nvme-fabrics: reset admin connection for secure concatenation
nvmet-tcp: support secure channel concatenation
crypto/Makefile | 1 +
crypto/hkdf.c | 112 +++++++++
drivers/nvme/common/auth.c | 303 +++++++++++++++++++++++++
drivers/nvme/common/keyring.c | 50 ++++
drivers/nvme/host/auth.c | 100 +++++++-
drivers/nvme/host/fabrics.c | 34 ++-
drivers/nvme/host/fabrics.h | 3 +
drivers/nvme/host/tcp.c | 65 +++++-
drivers/nvme/target/auth.c | 72 +++++-
drivers/nvme/target/fabrics-cmd-auth.c | 49 +++-
drivers/nvme/target/fabrics-cmd.c | 26 ++-
drivers/nvme/target/nvmet.h | 38 +++-
drivers/nvme/target/tcp.c | 23 +-
fs/crypto/hkdf.c | 68 +-----
include/crypto/hkdf.h | 18 ++
include/linux/nvme-auth.h | 7 +
include/linux/nvme-keyring.h | 7 +
include/linux/nvme.h | 7 +
18 files changed, 889 insertions(+), 94 deletions(-)
create mode 100644 crypto/hkdf.c
create mode 100644 include/crypto/hkdf.h
--
2.35.3
next reply other threads:[~2024-07-18 15:07 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-07-18 15:06 Hannes Reinecke [this message]
2024-07-18 15:06 ` [PATCH 1/8] crypto,fs: Separate out hkdf_extract() and hkdf_expand() Hannes Reinecke
2024-07-18 23:14 ` Eric Biggers
2024-07-19 6:13 ` Hannes Reinecke
2024-07-18 15:06 ` [PATCH 2/8] nvme: add nvme_auth_generate_psk() Hannes Reinecke
2024-07-18 15:06 ` [PATCH 3/8] nvme: add nvme_auth_generate_digest() Hannes Reinecke
2024-07-18 15:06 ` [PATCH 4/8] nvme: add nvme_auth_derive_tls_psk() Hannes Reinecke
2024-07-18 15:06 ` [PATCH 5/8] nvme-keyring: add nvme_tls_psk_refresh() Hannes Reinecke
2024-07-18 15:06 ` [PATCH 6/8] nvme-tcp: request secure channel concatenation Hannes Reinecke
2024-07-21 11:27 ` Sagi Grimberg
2024-07-22 6:36 ` Hannes Reinecke
2024-07-22 8:43 ` Hannes Reinecke
2024-07-18 15:06 ` [PATCH 7/8] nvme-fabrics: reset admin connection for secure concatenation Hannes Reinecke
2024-07-18 15:06 ` [PATCH 8/8] nvmet-tcp: support secure channel concatenation Hannes Reinecke
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240718150658.99580-1-hare@kernel.org \
--to=hare@kernel.org \
--cc=hch@lst.de \
--cc=kbusch@kernel.org \
--cc=linux-nvme@lists.infradead.org \
--cc=sagi@grimberg.me \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.