[strongSwan] AESNI and PCLMULQDQ support for Strongswan

Igor Lopez Orbe igorlor at gmail.com
Mon Jul 9 11:57:55 CEST 2012


Hello everyone,

I am trying to set up the AESNI support AES-GCM using the following
encryption algorithm in the ipsec.conf:
esp=aes128gcm16!

I have recompiled the kernel to add AESNI support and
ghash_clmulni_intel support but unfortunately when i set up the VPN i
check the ghash_clmulni_intel module and is never used. Does anyone
know if there is another cipher algorithm in strongswan to force to
use ghash_clmulni_intel module?

This functionality should be supported because in the following
Intel's Whitepaper they use strongswan with this support:
http://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=2&ved=0CFIQFjAB&url=http%3A%2F%2Fdownload.intel.com%2Fdesign%2Fintarch%2Fpapers%2F324238.pdf&ei=oar6T4bxGfOW0QXLtoC7Bw&usg=AFQjCNGSbze0jNl77RY1aW0WRqJ9x65Dbw&sig2=SI3vaMg0FaIpjpiLT7B7kQ

Any idea?

Thank you in advance,

igorlor




More information about the Users mailing list