Re: [Ocf-linux-users] Some questions about how to use OCF with linux kernel 2.6.31 native IPSec and
Brought to you by:
david-m
From: David M. <Dav...@se...> - 2010-01-07 11:54:27
|
Jivin mix.kao lays it down ... > Hi there, > > sorry for bothering, i have some questions need your help. > > 1. My platform is ARM with IXP425, can OCF, Openswan, and Linux kernel > 2.6.31 with native IPSec stack support IXP425 crypto hardware > acceleration? Or i have to use Openswan with KLIPS patch in kernel? netkey (native ipsec stack) will not use OCF. There is native IXP crypto in 2.6.31. I have't used it but we are looking at trying it out soon. For OCF, use the latest openswan-2.6.24rc5 from openswan.org and you shouldn't have to patch your kernel. > 2. I have patched the OCF into Linux kernel, if i want to use IXP425 > hardware crypto acceleration, what kernel options should i enable? > Attached screen shot is my kernel OCF config, is it correct or what > options should i select? The related options I run are: CONFIG_KLIPS=m CONFIG_KLIPS_ESP=y CONFIG_KLIPS_AH=y # CONFIG_KLIPS_AUTH_HMAC_MD5 is not set # CONFIG_KLIPS_AUTH_HMAC_SHA1 is not set # CONFIG_KLIPS_ALG is not set # CONFIG_KLIPS_ENC_3DES is not set CONFIG_KLIPS_IPCOMP=y CONFIG_KLIPS_OCF=y CONFIG_KLIPS_DEBUG=y CONFIG_KLIPS_IF_MAX=4 CONFIG_OCF_OCF=m # CONFIG_OCF_RANDOMHARVEST is not set CONFIG_OCF_CRYPTODEV=m # CONFIG_OCF_CRYPTOSOFT is not set # CONFIG_OCF_SAFE is not set CONFIG_OCF_IXP4XX=m # CONFIG_OCF_IXP4XX_SHA1_MD5 is not set # CONFIG_OCF_HIFN is not set # CONFIG_OCF_HIFNHIPP is not set # CONFIG_OCF_TALITOS is not set # CONFIG_OCF_EP80579 is not set # CONFIG_OCF_CRYPTOCTEON is not set # CONFIG_OCF_OCFNULL is not set # CONFIG_OCF_BENCH is not set Cheers, Davidm -- David McCullough, dav...@se..., Ph:+61 734352815 McAfee - SnapGear http://www.snapgear.com http://www.uCdot.org |