^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 1) # SPDX-License-Identifier: GPL-2.0-only
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 2) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 3) # TLS configuration
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 4) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 5) config TLS
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 6) tristate "Transport Layer Security support"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 7) depends on INET
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 8) select CRYPTO
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 9) select CRYPTO_AES
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 10) select CRYPTO_GCM
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 11) select STREAM_PARSER
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 12) select NET_SOCK_MSG
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 13) default n
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 14) help
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 15) Enable kernel support for TLS protocol. This allows symmetric
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 16) encryption handling of the TLS protocol to be done in-kernel.
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 17)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 18) If unsure, say N.
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 19)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 20) config TLS_DEVICE
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 21) bool "Transport Layer Security HW offload"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 22) depends on TLS
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 23) select SOCK_VALIDATE_XMIT
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 24) default n
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 25) help
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 26) Enable kernel support for HW offload of the TLS protocol.
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 27)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 28) If unsure, say N.
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 29)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 30) config TLS_TOE
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 31) bool "Transport Layer Security TCP stack bypass"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 32) depends on TLS
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 33) default n
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 34) help
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 35) Enable kernel support for legacy HW offload of the TLS protocol,
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 36) which is incompatible with the Linux networking stack semantics.
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 37)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 38) If unsure, say N.