Netdev 0x17 venue
Vancouver, Canada
Previous editions
Fosstodon
NETDEV VIDEOS
Session
TLS handshake for in-kernel consumers
Speakers
Chuck Lever
Label
Nuts and Bolts
Session Type
Bof
Contents
Description
Overview via slides:
- Why kernel consumers want TLS handshake (our use cases)
- Alternative approaches to providing TLS handshake in the kernel
- The netlink upcall and the user space agent we implemented (now upstream)
- Thoughts on the use of TPM, NIC offload, keyrings, and other technologies
Followed by open discussion, questions, and rotten fruit projectiles.
More technically:
The SunRPC, SMB, and NVMe protocols all now support the use of TLS, and Linux implements those protocols in the kernel proper. QUICv1 is also a potential consumer of a handshake service.
The authors implemented a netlink upcall mechanism that passes an open socket to user space so that an existing library implementation of TLS handshake can be used rather than adding handshake code to the kernel. The purpose of this mechanism is to provide a handshake service for kernel consumers of TLS, it is not for use by user space applications.
We will discuss work that has already been merged upstream, starting with 3b3009ea8abb (“net/handshake: Create a NETLINK service for handling handshake requests”). During the BoF we will discuss the architecture and usage of this new mechanism in addition to kernel consumers that have already adopted the new mechanism.
Recent News
Group Booking Discount at Paradox Hotel
[Mon, 16, Oct. 2023]
Bronze Sponsor, Relianoid
[Fri, 06, Oct. 2023]
Registration is now Open
[Mon, 18, Sep. 2023]
Bronze Sponsor, NVIDIA
[Fri, 15, Sep. 2023]
Silver Sponsor, Intel®
[Tue, 12, Sep. 2023]
Important Dates
Closing of CFS | Aug 27th, 2023 |
Notification by | Sep 15th, 2023 |
Conference dates | Oct 30th - Nov 3rd, 2023 |