Toot

Written by Electronic Eel on 2024-03-11 at 22:07

Setting up the hardware offload was totally easy and painless:

ssl_conf_command Options KTLS; in nginx.conf and then ethtool -K tls-hw-tx-offload on; ethtool -K tls-hw-rx-offload on;, for both nics of the bond.

An easy way to verify is looking at /proc/net/tls_stat.

A website with some helpful info is https://delthas.fr/blog/2023/kernel-tls/ , although the info that only AES128 works seems to be outdated as I got AES256 to work without problems as long as I stayed in TLS1.2.

=> More informations about this toot | View the thread | More toots from electronic_eel@treehouse.systems

Mentions

Tags

Proxy Information
Original URL
gemini://mastogem.picasoft.net/toot/112079329545014521
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
229.760641 milliseconds
Gemini-to-HTML Time
0.575386 milliseconds

This content has been proxied by September (ba2dc).