Linux 4.13: kernel handles TLS encryption itself
Summary
In 2017 Linux 4.13 was able to take over the encryption and decryption of a TLS connection itself for the first time. This was meant to improve performance and open up new uses. The complex connection setup, however, is still handled by libraries such as OpenSSL in user space.
Ideas
- The kernel only takes over symmetric encryption after the handshake.
- The error-prone handshake remains in proven libraries.
- Encryption in the kernel allows efficient data transfer without a detour through user space.
Insights
- Dividing the work between kernel and library combines performance with maintainability.
- Encryption moves to where the data flows anyway.
Facts
- Kernel TLS arrived with Linux 4.13 in September 2017.
- Libraries such as OpenSSL remain responsible for setting up the connection.
References
Critique
- The report gives no measurements for the promised performance gain.
Remarks
- Kernel TLS (kTLS) is used today by OpenSSL 3 and nginx and allows TLS offload to suitable network cards.
Recommendations
- On high-throughput web servers, check whether kTLS can be used together with sendfile.
- Only use kTLS if kernel, library and server support it together.
Links to the original source and the Web Archive open in a new tab.