openssl with aes-in or padlock

Wojciech Puchar wojtek at puchar.net
Sat Sep 13 07:34:48 UTC 2014


>> MUCH faster with AES-NI.
>
> Well, AES-NI CBC may be faster w/ AES-NI, but it's not as fast as using
> another mode...  AES-XTS should be many times faster than CBC...  Also,

30% maybe with geli.

> above you compared two different modes... on CBC encrypt (the OpenSSL
> test) and CBC decrypt (the geli test) so of course you're going to get
> very different performances...
>
> You didn't tell me if you're using a new enough version of OpenSSL or
> not..  What release are you using?  iirc, 10.0-R was the first release
OpenSSL 1.0.1e-freebsd 11 Feb 2013



More information about the freebsd-hackers mailing list