ื ื˜ืคืœื™ืงืก ืคืจืกืžื” ืชื™ืงื•ื ื™ ื™ื™ืฉื•ื TLS ืขื‘ื•ืจ ืœื™ื‘ืช FreeBSD

ื—ื‘ืจืช ื ื˜ืคืœื™ืงืก ืžื•ึผืฆึธืข ืœื‘ื“ื™ืงืช ื”ื˜ืžืขื” ื‘ืจืžืช ืœื™ื‘ืช FreeBSD ืฉืœ TLS (KTLS), ื”ืžืืคืฉืจืช ืขืœื™ื™ื” ืžืฉืžืขื•ืชื™ืช ื‘ื‘ื™ืฆื•ืขื™ ื”ื”ืฆืคื ื” ืขื‘ื•ืจ ืฉืงืขื™ TCP. ืชื•ืžืš ื‘ื”ืืฆืช ื”ืฆืคื ื” ืฉืœ ื ืชื•ื ื™ื ืžืฉื•ื“ืจื™ื ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœื™ TLS 1.0 ื•-1.2 ื”ื ืฉืœื—ื™ื ืœืฉืงืข ื‘ืืžืฆืขื•ืช ืคื•ื ืงืฆื™ื•ืช ื”ื›ืชื™ื‘ื”, aio_write ื•- sendfile.

ื—ื™ืœื•ืคื™ ืžืคืชื—ื•ืช ื‘ืจืžืช ืœื™ื‘ื” ืื™ื ื ื ืชืžื›ื™ื ื•ื™ืฉ ืœื™ืฆื•ืจ ืชื—ื™ืœื” ืืช ื”ื—ื™ื‘ื•ืจ ื•ืœื ื”ืœ ืžืฉื ื•ืžืชืŸ ื‘ืžืจื—ื‘ ื”ืžืฉืชืžืฉ. ื›ื“ื™ ืœื”ืขื‘ื™ืจ ืœืงืจื ืœ ืืช ืžืคืชื— ื”-Session ืฉื”ื•ืฉื’ ื‘ืชื”ืœื™ืš ื”ืžืฉื ื•ืžืชืŸ ืขืœ ื”ื—ื™ื‘ื•ืจ ืขื‘ื•ืจ ืฉืงืขื™ื, ื ื•ืกืคื” ื”ืืคืฉืจื•ืช TCP_TXTLS_ENABLE, ืฉืœืื—ืจ ื”ืคืขืœืชื” ื›ืœ ื”ื ืชื•ื ื™ื ืฉื ืฉืœื—ื• ืœืฉืงืข ื™ื•ื›ื ืกื• ืœืžืกื’ืจื•ืช TLS ื‘ืืžืฆืขื•ืช ื”ืžืคืชื— ืฉืฆื•ื™ืŸ. ื›ื“ื™ ืœืฉืœื•ื— ื”ื•ื“ืขื•ืช ืฉื™ืจื•ืช, ืœืžืฉืœ ื›ื“ื™ ืœื ื”ืœ ืžืฉื ื•ืžืชืŸ ืขืœ ื—ื™ื‘ื•ืจ, ืขืœื™ืš ืœื”ืฉืชืžืฉ ื‘ืคื•ื ืงืฆื™ื” sendmsg ืขื ืกื•ื’ ื”ืจืฉื•ืžื” TLS_SET_RECORD_TYPE.

ืฉืชื™ ืฉื™ื˜ื•ืช ืขื™ืงืจื™ื•ืช ืœื”ืฆืคื ืช ืžืกื’ืจื•ืช TLS ื ืชืžื›ื•ืช: ืชื•ื›ื ื” ื•-ifnet (ื‘ืืžืฆืขื•ืช ื”ืืฆืช ื—ื•ืžืจื” ืฉืœ ื›ืจื˜ื™ืกื™ ืจืฉืช). ื‘ื—ื™ืจืช ื”ืฉื™ื˜ื” ืžืชื‘ืฆืขืช ื‘ืืžืฆืขื•ืช
ืืคืฉืจื•ื™ื•ืช ืฉืงืข TCP_TXTLS_MODE. ืฉื™ื˜ืช ื”ืชื•ื›ื ื” ืžืืคืฉืจืช ืœื—ื‘ืจ ืงืฆื” ืขื•ืจืคื™ ืฉื•ื ื™ื ืœื”ืฆืคื ื”. ื›ื“ื•ื’ืžื”, ืคื•ืจืกื ื”-backend ืฉืœ ktls_ocf.ko ืขื ืชืžื™ื›ื” ื‘-AES-GCM, ื”ืžื™ื•ืฉื ืขืœ ื‘ืกื™ืก ืžืกื’ืจืช OpenCrypto. ืžืกืคืจ ืžืขืจื›ื•ืช ืžื•ืฆืขื•ืช ืœื ื™ื”ื•ืœ ื‘ืกื ื™ืฃ kern.ipc.tls.*. ื‘ืขืช ื‘ื ื™ื™ืช ื”ืœื™ื‘ื”, ืชืžื™ื›ืช TLS ืžื•ืคืขืœืช ื‘ืืžืฆืขื•ืช ืืคืฉืจื•ืช KERN_TLS.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”