Toot

Written by Electronic Eel on 2024-03-11 at 22:06

Another problem I found is that the TLS hardware offload only seems to support TLS 1.2 ciphers. The datasheet from Mellanox/Nvidia claims "AES-GCM 128/256-bit key" and doesn't give more details.

It worked with the TLS 1.2 cipher ECDHE-RSA-AES256-GCM-SHA384. But as soon as I switched to TLS 1.3 and tried to use for example TLS_AES_256_GCM_SHA384, the kernel didn't use the hardware offload anymore. I'm not a crypto expert, but I'd say that encrypting the actual data after setting up the TLS session once should be the same for both. So it could be a kernel issue.

=> More informations about this toot | View the thread | More toots from electronic_eel@treehouse.systems

Mentions

Tags

Proxy Information
Original URL
gemini://mastogem.picasoft.net/toot/112079327314342771
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
223.850404 milliseconds
Gemini-to-HTML Time
0.587031 milliseconds

This content has been proxied by September (ba2dc).