AES Crypto Support in Kernel

Simo idra at samba.org
Mon May 6 11:11:21 MDT 2013


On 05/06/2013 10:22 AM, Jeff Layton wrote:
> On Mon, 6 May 2013 09:11:28 -0500
> Steve French <smfrench at gmail.com> wrote:
>
>> Shirish,
>> Does the recent crypto merge to kernel, which includes these two
>> patches for example, help you (at least on the more common chips,
>> those with optimized AES offload support)?  Wonder if we can leverage
>> the hardware offload in Samba?
>>
> Doesn't samba use the NSS libs for this? If so, then they should
> already be using the hardware offload since it does internally.

We don't, we use GSSAPI libraries for AES and I am not sure there is HW 
optimization yet.
However I would let vendors deal with that, we have no control what 
libraries are installed, we should just try to use the OS libraries 
instead of trying to do our own so as to make life easier for users and 
vendors.

Simo.


More information about the samba-technical mailing list