aesni module with AMD CPUs?

Dennis Glatting freebsd at pki2.com
Sat Feb 4 21:46:05 UTC 2012


On Sat, 2012-02-04 at 20:28 +0200, Konstantin Belousov wrote:
> On Sat, Feb 04, 2012 at 10:14:18AM -0800, Dennis Glatting wrote:
> > On Sat, 2012-02-04 at 20:04 +0200, Konstantin Belousov wrote:
> > > On Sat, Feb 04, 2012 at 09:41:54AM -0800, Dennis Glatting wrote:
> > > > On Sat, 2012-02-04 at 09:10 -0800, Dennis Glatting wrote:
> > > > > > What is written into dmesg after the load ?
> > > > > > Try to restart sshd and log into the system over ssh after aesni(4)
> > > > > and
> > > > > > cryptodev(4) modules are loaded.
> > > > > 
> > > > 
> > > > Sorry, BD3 is in the process of being updated to pick up the LSI patches
> > > > (Thank you LSI and others).
> > > > 
> > > > 
> > > > On BD3:
> > > > 
> > > > 
> > > > bd3# kldload aesni
> > > > bd3# kldstat | grep -i aesni
> > > >  8    1 0xffffffff81768000 1a2b     aesni.ko
> > > > bd3# /etc/rc.d/sshd restart
> > > > Stopping sshd.
> > > > Waiting for PIDS: 1832.
> > > > Starting sshd.
> > > > bd3#
> > > > 
> > > > 
> > > > 
> > > > On BTW:
> > > > 
> > > > 
> > > > btw> ssh -v dennisg at bd3
> > > > OpenSSH_5.4p1_hpn13v11 FreeBSD-20100308, OpenSSL 0.9.8q 2 Dec 2010
> > > > debug1: Reading configuration data /etc/ssh/ssh_config
> > > > debug1: Connecting to bd3.pki2.com [192.168.23.22] port 22.
> > > > debug1: Connection established.
> > > > debug1: identity file /home/dennis_glatting/.ssh/id_rsa type -1
> > > > debug1: identity file /home/dennis_glatting/.ssh/id_rsa-cert type -1
> > > > debug1: identity file /home/dennis_glatting/.ssh/id_dsa type -1
> > > > debug1: identity file /home/dennis_glatting/.ssh/id_dsa-cert type -1
> > > > debug1: Remote protocol version 2.0, remote software version
> > > > OpenSSH_5.8p2_hpn13v11 FreeBSD-20110503
> > > > debug1: match: OpenSSH_5.8p2_hpn13v11 FreeBSD-20110503 pat OpenSSH*
> > > > debug1: Enabling compatibility mode for protocol 2.0
> > > > debug1: Local version string SSH-2.0-OpenSSH_5.4p1_hpn13v11
> > > > FreeBSD-20100308
> > > > debug1: SSH2_MSG_KEXINIT sent
> > > > debug1: SSH2_MSG_KEXINIT received
> > > > debug1: kex: server->client aes128-ctr hmac-sha1 none
> > > > debug1: kex: client->server aes128-ctr hmac-sha1 none
> > > > debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(1024<2048<8192) sent
> > > > debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP
> > > > debug1: SSH2_MSG_KEX_DH_GEX_INIT sent
> > > > debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY
> > > > debug1: Host 'bd3.pki2.com' is known and matches the RSA host key.
> > > > debug1: Found key in /home/dennis_glatting/.ssh/known_hosts:41
> > > > debug1: ssh_rsa_verify: signature correct
> > > > debug1: SSH2_MSG_NEWKEYS sent
> > > > debug1: expecting SSH2_MSG_NEWKEYS
> > > > debug1: SSH2_MSG_NEWKEYS received
> > > > debug1: Roaming not allowed by server
> > > > debug1: SSH2_MSG_SERVICE_REQUEST sent
> > > > debug1: SSH2_MSG_SERVICE_ACCEPT received
> > > > debug1: Authentications that can continue:
> > > > publickey,keyboard-interactive
> > > > debug1: Next authentication method: publickey
> > > > debug1: Trying private key: /home/dennis_glatting/.ssh/id_rsa
> > > > debug1: Trying private key: /home/dennis_glatting/.ssh/id_dsa
> > > > debug1: Next authentication method: keyboard-interactive
> > > > Password:
> > > > debug1: Authentication succeeded (keyboard-interactive).
> > > > debug1: Final hpn_buffer_size = 2097152
> > > > debug1: HPN Disabled: 0, HPN Buffer Size: 2097152
> > > > debug1: channel 0: new [client-session]
> > > > debug1: Enabled Dynamic Window Scaling
> > > > 
> > > > debug1: Requesting no-more-sessions at openssh.com
> > > > debug1: Entering interactive session.
> > > > Last login: Sat Feb  4 09:38:12 2012 from btw.pki2.com
> > > > FreeBSD 9.0-STABLE (SMUNI) #2: Sat Feb  4 09:15:42 PST 2012
> > > > 
> > > > bd3>
> > > > 
> > > > 
> > > > Back to BD3:
> > > > 
> > > > bd3# dmesg|tail
> > > > da9 at mps2 bus 0 scbus4 target 0 lun 0
> > > > da9: <ATA WDC WD25EZRS-00J 0A80> Fixed Direct Access SCSI-6 device
> > > > da9: 300.000MB/s transfers
> > > > da9: Command Queueing enabled
> > > > da9: 2384658MB (4883781168 512 byte sectors: 255H 63S/T 304001C)
> > > > Trying to mount root from ufs:/dev/gpt/disk0 [rw]...
> > > > ZFS filesystem version 5
> > > > ZFS storage pool version 28
> > > > cryptosoft0: <software crypto> on motherboard
> > > > aesni0: <AES-CBC,AES-XTS> on motherboard
> > > > bd3#
> > > > 
> > > > 
> > > > bd3# tail /var/log/messages
> > > > 	(snip -- sorry)
> > > > Feb  4 09:38:18 bd3 su: dennisg to root on /dev/pts/0
> > > > Feb  4 09:38:22 bd3 kernel: cryptosoft0: <software crypto> on
> > > > motherboard
> > > > Feb  4 09:38:22 bd3 kernel: aesni0: <AES-CBC,AES-XTS> on motherboard
> > > > bd3#
> > > > 
> > > > 
> > > > 
> > > > I /assume/ sshd is using the driver. How would I know?
> > > 
> > > Without reading the code and possibly adding some printfs or logs, you
> > > cannot. But I do know that sshd prefer /dev/crypto when available, over
> > > the usermode algorithm implementation.
> > > 
> > > You can also look at the users of /dev/crypto, using "fuser /dev/crypto"
> > > command, and see what that pids are.
> > > 
> > 
> > Check that.
> > 
> > At this point I would have to do some reading but there is
> > no /dev/crypto. Whatever AESNI is doing, apparently creating /dev/crypto
> > isn't one of them. I loaded and looked on three machines: Two 8150s and
> > the 6274. All RELENG_9.
> > 
> > bd3# fuser /dev/crypto
> > fuser: /dev/crypto: No such file or directory
> > fuser: files not accessible
> > bd3#
> Did you load cryptodev ? I noted that in some previous message.

No. But now that I know about, :), I think this is what you want to see:


bd3# kldload aesni
bd3# kldload cryptodev
bd3# ls -l /dev/crypto
crw-rw-rw-  1 root  wheel    0, 146 Feb  4 13:40 /dev/crypto
bd3# 



bd3# /etc/rc.d/sshd restart
Stopping sshd.
Waiting for PIDS: 1832.
Starting sshd.
bd3# fuser /dev/crypto
/dev/crypto:  2052w
bd3# ps -ax| grep 2052
 2052  ??  Ss     0:00.00 /usr/sbin/sshd
 2055   1  RL+    0:00.00 grep 2052
bd3#



btw> ssh -v dennisg at bd3
OpenSSH_5.4p1_hpn13v11 FreeBSD-20100308, OpenSSL 0.9.8q 2 Dec 2010
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: Connecting to bd3.pki2.com [192.168.23.22] port 22.
debug1: Connection established.
debug1: identity file /home/dennis_glatting/.ssh/id_rsa type -1
debug1: identity file /home/dennis_glatting/.ssh/id_rsa-cert type -1
debug1: identity file /home/dennis_glatting/.ssh/id_dsa type -1
debug1: identity file /home/dennis_glatting/.ssh/id_dsa-cert type -1
debug1: Remote protocol version 2.0, remote software version
OpenSSH_5.8p2_hpn13v11 FreeBSD-20110503
debug1: match: OpenSSH_5.8p2_hpn13v11 FreeBSD-20110503 pat OpenSSH*
debug1: Enabling compatibility mode for protocol 2.0
debug1: Local version string SSH-2.0-OpenSSH_5.4p1_hpn13v11
FreeBSD-20100308
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: server->client aes128-ctr hmac-sha1 none
debug1: kex: client->server aes128-ctr hmac-sha1 none
debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(1024<2048<8192) sent
debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP
debug1: SSH2_MSG_KEX_DH_GEX_INIT sent
debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY
debug1: Host 'bd3.pki2.com' is known and matches the RSA host key.
debug1: Found key in /home/dennis_glatting/.ssh/known_hosts:41
debug1: ssh_rsa_verify: signature correct
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug1: SSH2_MSG_NEWKEYS received
debug1: Roaming not allowed by server
debug1: SSH2_MSG_SERVICE_REQUEST sent
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug1: Authentications that can continue:
publickey,keyboard-interactive
debug1: Next authentication method: publickey
debug1: Trying private key: /home/dennis_glatting/.ssh/id_rsa
debug1: Trying private key: /home/dennis_glatting/.ssh/id_dsa
debug1: Next authentication method: keyboard-interactive
Password:
debug1: Authentication succeeded (keyboard-interactive).
debug1: Final hpn_buffer_size = 2097152
debug1: HPN Disabled: 0, HPN Buffer Size: 2097152
debug1: channel 0: new [client-session]
debug1: Enabled Dynamic Window Scaling

debug1: Requesting no-more-sessions at openssh.com
debug1: Entering interactive session.
Last login: Sat Feb  4 13:28:09 2012 from btw.pki2.com
FreeBSD 9.0-STABLE (SMUNI) #2: Sat Feb  4 09:15:42 PST 2012

bd3>




bd3# lsof | grep crypto | grep sshd
sshd      1809    root  txt   VREG              0,131            1718000
95344175 /lib/libcrypto.so.6
sshd      1931    root  txt   VREG              0,131            1718000
95344175 /lib/libcrypto.so.6
sshd      1934 dennisg  txt   VREG              0,131            1718000
95344175 /lib/libcrypto.so.6
sshd      1984    root  txt   VREG              0,131            1718000
95344175 /lib/libcrypto.so.6
sshd      1987 dennisg  txt   VREG              0,131            1718000
95344175 /lib/libcrypto.so.6
sshd      2052    root  txt   VREG              0,131            1718000
95344175 /lib/libcrypto.so.6
sshd      2052    root    3u  VCHR              0,146                0t0
146 /dev/crypto














More information about the freebsd-amd64 mailing list