Repository navigation
Expand file tree
/
Copy pathREADME
More file actions
65 lines (44 loc) · 1.82 KB
/
Copy pathREADME
File metadata and controls
65 lines (44 loc) · 1.82 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
# Release Notes for ktls-utils 1.5.0
In-kernel TLS consumers need a mechanism to perform TLS handshakes
on a connected socket to negotiate TLS session parameters that can
then be programmed into the kernel's TLS record protocol engine.
This package of software provides a TLS handshake user agent that
listens for kernel requests and then materializes a user space
socket endpoint on which to perform these handshakes. The resulting
negotiated session parameters are passed back to the kernel via
standard kTLS socket options.
See [COPYING](COPYING) for the full text of the license under which
this package is released.
## Dependencies
### Run-time dependencies
The kernel must have net/handshake support (v6.5 or later) and be
built with the following CONFIG options enabled:
* CONFIG_TLS
* CONFIG_KEYS
* CONFIG_KEYS_REQUEST_CACHE
### Build dependencies
The build environment requires the development packages for the
following libraries to be installed:
* GnuTLS
* keyutils
* GLib-2.0
* libnl3
* libyaml
The Linux UAPI headers must be v5.10 or later. tlshd reads the
kernel's generic netlink attribute policy to detect optional
handshake features, and the definitions for that arrived in v5.10.
## Installation
See [NEWS](NEWS) to see what has changed in the latest release,
and see [INSTALL](INSTALL) for build instructions.
## Contributing
This project welcomes contributions from the community.
Before submitting a pull request,
please [review our contribution guide](./CONTRIBUTING.md).
See the GitHub Issue Tracker at
https://github.com/linux-nfs/ktls-utils/issues to review or open
to-do items.
## Security
Please consult the [security guide](./SECURITY.md) for our responsible security vulnerability disclosure process
## License
Copyright (c) 2023 Oracle and/or its affiliates.
Released under the GNU GENERAL PUBLIC LICENSE version 2