IPSec improvement

Slawa Olhovchenkov slw at zxy.spb.ru
Fri Jun 14 19:34:51 UTC 2013


On Fri, Jun 14, 2013 at 03:59:22PM +0200, VANHULLEBUS Yvan wrote:

> > > On Fri, Jun 14, 2013 at 02:36:15PM +0400, Slawa Olhovchenkov wrote:
> > > > I am plan to do some improve in IPSec stack:
> > > > 
> > > > - AES-GCM support (from OpenBSD)
> > > 
> > > Dylan Castine already started to work on that last year (see ML's
> > > archives), and we took some time to work together on that.
> > > 
> > > Unfortunately, patch hasn't been commited since, as Dylan needed some
> > > more time to do some important cleanups on the code.
> > > 
> > > I'll try to recontact Dylan to see if he could take time to finish
> > > that.
> > 
> > OK, you inform about progress in this list?
> 
> Yep.
> 
> Just for information, Dylan also talked about such code last year, but
> the patch I got were from Riaan Kruger.
> I just sent him a mail on that subject.
> 
> The patchset Riaan provided me was working on basic tests.
> On the benchmark we did, software AES-GCM was faster than software
> AES-CBC+SHA1, but slower than hardware accelerated AES-CBC+SHA1 (tried
> with both VIA's Padlock and Intel's AESNI).

Can I see this patches?
This patches must implement infrastructure for combined algoritms,
GOST/GOST R also is combined algoritm.


More information about the freebsd-net mailing list