Netdev List
 help / color / mirror / Atom feed
* Kernel TLS in 4.13-rc1
@ 2017-07-23 19:39 David Oberhollenzer
  2017-07-24 21:10 ` Dave Watson
  0 siblings, 1 reply; 4+ messages in thread
From: David Oberhollenzer @ 2017-07-23 19:39 UTC (permalink / raw)
  To: netdev; +Cc: davejwatson, Richard Weinberger

Hi!

I recently wanted to take a look at the kernel TLS support that
made it into 4.13-rc1, but ran into some issues.

After fixing the benchmark/test tool that the patch description
linked to (https://github.com/Mellanox/tls-af_ktls_tool) to make
sure that the server and client actually *agree* on AES-128-GCM,
I simply ran the client program with the --verify-sendpage option.

The handshake and setting up of the sockets appears to work but
the program complains that the sent and received page contents
do not match (sent is 0x12 repeated all over and received looks
pretty random).

I compiled the 4.13-rc1 tarball from kernel.org with
defconfig/kvmconfig for x86_64 and ran it on qemu using a
freshly debootstraped Debian sid rootfs.

I previously also tried it on a physical machine (localmodconfig,
also x86_64), running CentOS 7 and a custom build of recent gnutls
and its dependencies, with the same results.

Surely somebody must have tested this before it was merged? What
am I missing? Am I using a broken version of the benchmark tool
or am I holding it wrong?


Thanks,

David

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2017-07-31 22:00 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-07-23 19:39 Kernel TLS in 4.13-rc1 David Oberhollenzer
2017-07-24 21:10 ` Dave Watson
2017-07-30 21:14   ` David Oberhollenzer
2017-07-31 22:00     ` Dave Watson

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox