> So this is the kind of thing I could point at a crypto engine
> if I had one?

If, if, if....

IF you had a crypto engine, and IF you had the OpenSSL package compiled
with the IBM modifications to enable the Cryptoki crypto interface to
the crypto engine, and IF you had OpenSSH recompiled to use the modified
OpenSSL libraries, and IF all this didn't do harm to your support
agreement, then you could probably get some benefit.

Right now, all the ssh crypto is done in software, and CVS does a lot of
connection setup and teardown which is where the asymmetric crypto (the
really expensive part of the crypto exchange) gets done. Use of the
routines in Cryptoki would help, but as you can see from above, it's not
gonna be simple.

----------------------------------------------------------------------
For LINUX-390 subscribe / signoff / archive access instructions,
send email to [EMAIL PROTECTED] with the message: INFO LINUX-390 or visit
http://www.marist.edu/htbin/wlvindex?LINUX-390

Reply via email to