From: Stephan Mueller <smueller@chronox.de>
To: David Woodhouse <dwmw2@infradead.org>
Cc: Marcel Holtmann <marcel@holtmann.org>,
Herbert Xu <herbert@gondor.apana.org.au>,
linux-crypto@vger.kernel.org,
linux-kernel <linux-kernel@vger.kernel.org>,
linux-api@vger.kernel.org, David Howells <dhowells@redhat.com>
Subject: Re: [PATCH v2 0/5] crypto: add algif_akcipher user space API
Date: Tue, 27 Oct 2015 11:50:04 +0100 [thread overview]
Message-ID: <9859277.cZClo5B21s@tauon.atsec.com> (raw)
In-Reply-To: <1445937541.3405.75.camel@infradead.org>
Am Dienstag, 27. Oktober 2015, 18:19:01 schrieb David Woodhouse:
Hi David,
>
>That's largely orthogonal to the point Marcel was making.
>
>The point is that akcipher is limited to using keys for which we have
>the private key material available directly in software. We cannot
Agreed.
>expose that critically limited API to userspace. We need to expose an
>API which supports hardware keys, and basically that means using the
>kernel's key subsystem.
Agreed. But at the same time, that interface should be able to support the use
case where the software wants to be in control (just take OpenSSL as the
simple example where you can add an engine for the Linux kernel backed RSA
operation).
Note, the goal with AF_ALG is simply to expose asymmetric hardware support to
user space for unspecified use cases to make user space faster.
>
>For a key which *happens* to be in software, the key subsystem may end
>up *using* akcipher behind the scenes. But the API we expose to
>userspace cannot simply be based on akcipher.
So, how do you propose that would work? Based on what I understand the
suggested logic flow for a simple OpenSSL-like approach would be:
1. OpenSSL opens the interface with the kernel key subsystem and sends the
pub/priv key along
2. the key subsystem hooks the key in
3. the key subsystem sees that there is a simple RSA operation to be made
4. the key subsystem initiates an akcipher operation and sends the keys along
5. the akcipher returns the cipher result to the key subsystem
6. the key subsystem sends the data to user space
Currently I fail to understand why that key subsystem would help me in that
common use case (note, I totally understand to use the key subsystem when you
have some key management schema in place).
Also, I fail to see that this logic flow would be fast to warrant a detour
from user land into kernel land for an RSA operation.
Thanks
Stephan
next prev parent reply other threads:[~2015-10-27 10:50 UTC|newest]
Thread overview: 30+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-10-18 10:44 Stephan Mueller
2015-10-18 10:45 ` [PATCH v2 1/5] MPI: fix off by one in mpi_read_raw_from_sgl Stephan Mueller
2015-10-19 23:25 ` Tadeusz Struk
2015-10-20 14:20 ` Herbert Xu
2015-10-18 10:46 ` [PATCH v2 2/5] crypto: AF_ALG -- add sign/verify API Stephan Mueller
2015-10-18 10:47 ` [PATCH v2 3/5] crypto: AF_ALG -- add setpubkey setsockopt call Stephan Mueller
2015-10-30 8:16 ` Marcel Holtmann
2015-10-30 8:42 ` Stephan Mueller
2015-10-18 10:48 ` [PATCH v2 4/5] crypto: AF_ALG -- add asymmetric cipher interface Stephan Mueller
2015-10-18 10:49 ` [PATCH v2 5/5] crypto: algif_akcipher - enable compilation Stephan Mueller
2015-10-19 1:32 ` [PATCH v2 0/5] crypto: add algif_akcipher user space API Herbert Xu
2015-10-19 7:14 ` Stephan Mueller
2015-10-19 7:27 ` Herbert Xu
2015-10-27 4:54 ` Marcel Holtmann
2015-10-27 9:12 ` Stephan Mueller
2015-10-27 9:19 ` David Woodhouse
2015-10-27 10:50 ` Stephan Mueller [this message]
2015-10-27 23:15 ` David Woodhouse
2015-10-27 23:35 ` Stephan Mueller
2015-10-27 23:43 ` David Woodhouse
2015-10-27 23:47 ` Stephan Mueller
2015-10-28 0:37 ` David Woodhouse
2015-10-28 1:18 ` Stephan Mueller
2015-10-28 1:36 ` David Woodhouse
2015-10-28 0:46 ` Marcel Holtmann
2015-10-28 1:29 ` Stephan Mueller
2015-10-28 2:56 ` Marcel Holtmann
2015-10-28 10:12 ` Stephan Mueller
2015-10-27 15:16 ` Tadeusz Struk
2015-12-14 18:06 ` Tadeusz Struk
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=9859277.cZClo5B21s@tauon.atsec.com \
--to=smueller@chronox.de \
--cc=dhowells@redhat.com \
--cc=dwmw2@infradead.org \
--cc=herbert@gondor.apana.org.au \
--cc=linux-api@vger.kernel.org \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=marcel@holtmann.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®