11d8e [Crypto] Poor performance with AESNI GELI - Page 2 - The FreeBSD Forums
The FreeBSD Forums  

Go Back   The FreeBSD Forums > Base System > Storage

Storage Place to ask questions about partitioning, labelling, filesystems, encryption or anything else related to storage area.

Reply
 
Thread Tools Display Modes
  #26  
Old July 29th, 2012, 14:13
Sebulon's Avatar
Sebulon Sebulon is offline
Member
 
Join Date: Nov 2010
Location: Uppsala, Sweden
Posts: 559
Thanks: 24
Thanked 94 Times in 78 Posts
Default

@lockdoc

Not that big of a difference, but measureable. The numbers are all there.

/Sebulon
Reply With Quote
  #27  
Old July 29th, 2012, 16:19
lockdoc lockdoc is offline
Member
 
Join Date: Jul 2009
Posts: 122
Thanks: 3
Thanked 6 Times in 5 Posts
Default

Quote:
Originally Posted by Sebulon View Post
@lockdoc
Not that big of a difference, but measureable. The numbers are all there.
/Sebulon
I meant the keyfile. You only have used one.
Quote:
Originally Posted by Sebulon
dd if=/dev/random of=/boot/geli/disks.key bs=64 count=1
Reply With Quote
  #28  
Old July 29th, 2012, 16:43
Sebulon's Avatar
Sebulon Sebulon is offline
Member
 
Join Date: Nov 2010
Location: Uppsala, Sweden
Posts: 559
Thanks: 24
Thanked 94 Times in 78 Posts
Default

@lockdoc

Ahh, OK, now I get it. Yes, I only used the same key, with the lenght described in the Handbook. In case it affected performance, the results wouldn't have been comparable.

/Sebulon
Reply With Quote
  #29  
Old August 4th, 2012, 09:56
lockdoc lockdoc is offline
Member
 
Join Date: Jul 2009
Posts: 122
Thanks: 3
Thanked 6 Times in 5 Posts
Default

Anyone know what the security difference between AES-XTS and AES-CBS is?
I mean, as seen from the benchmarks above I would like to migrate to AES-CBC, but only if it is as secure as XTS.
Reply With Quote
  #30  
Old August 4th, 2012, 20:19
vermaden's Avatar
vermaden vermaden is offline
Giant Locked
 
Join Date: Nov 2008
Location: pl_PL.lodz
Posts: 2,210
Thanks: 60
Thanked 637 Times in 352 Posts
Default

@lockdoc

Its already described here in this thread:
http://forums.freebsd.org/showpost.p...1&postcount=21
__________________
Religions, worst damnation of mankind.
"FreeBSD has always been the operating system that GNU/Linux should have been." Frank Pohlmann, IBM
http://vermaden.blogspot.com
Reply With Quote
  #31  
Old August 5th, 2012, 12:49
lockdoc lockdoc is offline
Member
 
Join Date: Jul 2009
Posts: 122
Thanks: 3
Thanked 6 Times in 5 Posts
Default

Quote:
Originally Posted by vermaden View Post
@lockdoc

Its already described here in this thread:
http://forums.freebsd.org/showpost.p...1&postcount=21
Yes I posted that. But again, if you read this
Quote:
...XTS will be more fast since you can do parallel operations.
And then compare it to the benchmarks the users have done in this forum, it all doesnt make sense, as CBC seems to be faster.

Quote:
...XTS have some strong design on some attacks...
I cannot extract security related information from that. So the question is still open.
Reply With Quote
  #32  
Old August 5th, 2012, 20:32
vermaden's Avatar
vermaden vermaden is offline
Giant Locked
 
Join Date: Nov 2008
Location: pl_PL.lodz
Posts: 2,210
Thanks: 60
Thanked 637 Times in 352 Posts
Default

I have read that both CBC and XTS are bing considered secure, its like AES vs blowfish debate, but I am not that into cryptography to tell You exact differences to tell You which one is more secure.

Below are real world benchmark results from some user of these forums, all WITH aesni(4), one without:

Code:
ALGORITHM     BIT  MB/s
NONE           -   146
AES-XTS       128   70
AES-CBC       128  114 (65 without AESNI)
Blowfish-CBC  128   28
Camellia-CBC  128   43
3DES-CBC      192   14
AES-XTS       256   68
AES-CBC       256  106
Blowfish-CBC  256   28
Camellia-CBC  256   37
__________________
Religions, worst damnation of mankind.
"FreeBSD has always been the operating system that GNU/Linux should have been." Frank Pohlmann, IBM
http://vermaden.blogspot.com
Reply With Quote
  #33  
Old May 28th, 2013, 19:42
nterupt nterupt is offline
Junior Member
 
Join Date: Nov 2012
Posts: 1
Thanks: 0
Thanked 0 Times in 0 Posts
Default

Quote:
Originally Posted by mmoll View Post
Hi,
if you use 9.x, have a look at the following patches which were commited to 10.x but not MFCed:
http://www.secnetix.de/olli/FreeBSD/...ex.py?r=226837
http://www.secnetix.de/olli/FreeBSD/...ex.py?r=226840
I am currently using FreeBSD 9.1 x64 and AES-XTS 256. I am having some performance issues and was wondering 1) how I can tell whether this has made it into 9.1 and 2) if not, what would be the best way for me to pull into this change onto my system.
Reply With Quote
  #34  
Old May 28th, 2013, 22:49
mmoll mmoll is offline
Junior Member
 
Join Date: Mar 2010
Posts: 36
Thanks: 3
Thanked 5 Times in 5 Posts
Default

Hi,

Quote:
Originally Posted by nterupt View Post
1) how I can tell whether this has made it into 9.1
They haven't.
Quote:
Originally Posted by nterupt View Post
2) if not, what would be the best way for me to pull into this change onto my system.
From the links above, you can get diffs/patches, which you can apply to your 9.x sources and rebuild the kernel.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
[PF] Poor network performance with PF firewall pva Firewalls 4 October 9th, 2011 16:19
poor network performance jsibsd Networking 8 March 16th, 2011 06:58
Poor samba performance palmboy5 Web & Network Services 8 January 11th, 2011 10:56
[Solved] Poor RAID performance erikf154 System Hardware 3 February 10th, 2010 10:38
[Solved] opera-10 poor performance warudemaru Installation and Maintenance of FreeBSD Ports or Packages 13 October 18th, 2009 05:40


All times are GMT +1. The time now is 05:17.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.
The mark FreeBSD is a registered trademark of The FreeBSD Foundation and is used by The FreeBSD Project with the permission of The FreeBSD Foundation.
Web protection and acceleration provided by CloudFlare
0