From mboxrd@z Thu Jan 1 00:00:00 1970 From: "De Lara Guarch, Pablo" Subject: Re: [PATCH] examples/l2fwd-crypto: fix verify with decrypt in chain Date: Thu, 13 Oct 2016 18:22:21 +0000 Message-ID: References: <1476262724-164925-1-git-send-email-piotrx.t.azarewicz@intel.com> <60ABE07DBB3A454EB7FAD707B4BB158213B046F3@IRSMSX109.ger.corp.intel.com> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Cc: "dev@dpdk.org" To: "Jastrzebski, MichalX K" , "Azarewicz, PiotrX T" , "Yang, GangX" Return-path: Received: from mga02.intel.com (mga02.intel.com [134.134.136.20]) by dpdk.org (Postfix) with ESMTP id 577D05591 for ; Thu, 13 Oct 2016 20:22:25 +0200 (CEST) In-Reply-To: <60ABE07DBB3A454EB7FAD707B4BB158213B046F3@IRSMSX109.ger.corp.intel.com> Content-Language: en-US List-Id: patches and discussions about DPDK List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: dev-bounces@dpdk.org Sender: "dev" > -----Original Message----- > From: Jastrzebski, MichalX K > Sent: Thursday, October 13, 2016 1:48 AM > To: Azarewicz, PiotrX T; De Lara Guarch, Pablo; Yang, GangX > Cc: dev@dpdk.org > Subject: RE: [dpdk-dev] [PATCH] examples/l2fwd-crypto: fix verify with > decrypt in chain >=20 > > -----Original Message----- > > From: dev [mailto:dev-bounces@dpdk.org] On Behalf Of Piotr Azarewicz > > Sent: Wednesday, October 12, 2016 10:59 AM > > To: De Lara Guarch, Pablo ; Yang, GangX > > > > Cc: dev@dpdk.org > > Subject: [dpdk-dev] [PATCH] examples/l2fwd-crypto: fix verify with decr= ypt > > in chain > > > > This patch fix setting crypto operation data parameters in l2fwd-crypto > > application. > > From now decryption in chain with auth verify work fine. > > > > How to reproduce the issue: > > > > 1. Run l2fwd_crypto with command: > > -c 0x3 -n 4 --vdev "crypto_aesni_mb" \ > > --vdev "crypto_aesni_mb" \ > > -- -p 0x3 --chain CIPHER_HASH \ > > --cipher_op ENCRYPT --cipher_algo AES_CBC \ > > --cipher_key 00:01:02:03:04:05:06:07:08:09:0a:0b:0c:0d:0e:0f \ > > --iv 00:01:02:03:04:05:06:07:08:09:0a:0b:0c:0d:0e:ff \ > > --auth_op GENERATE --auth_algo SHA1_HMAC \ > > --auth_key > > 11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11= : > > 11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11= : > > 11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11 > > > > 2. Send packet with payload and capture forwarded packet. > > Payload in forwarded packet is encrypted, what is good. > > > > 3. Run l2fwd_crypto with command: > > -c 0x3 -n 4 --vdev "crypto_aesni_mb" \ > > --vdev "crypto_aesni_mb" \ > > -- -p 0x3 --chain HASH_CIPHER \ > > --cipher_op DECRYPT --cipher_algo AES_CBC \ > > --cipher_key 00:01:02:03:04:05:06:07:08:09:0a:0b:0c:0d:0e:0f \ > > --iv 00:01:02:03:04:05:06:07:08:09:0a:0b:0c:0d:0e:ff \ > > --auth_op VERIFY --auth_algo SHA1_HMAC \ > > --auth_key > > 11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11= : > > 11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11= : > > 11:11:11:11:11:11:11:11:11:11:11:11:11:11:11:11 > > > > 4. Send earlier captured packet and capture forwarded packet. > > Payload in newly captured packet is not decrypted, what is wrong. > > > > Fixes: 387259bd6c67 ("examples/l2fwd-crypto: add sample application") > > > > Signed-off-by: Piotr Azarewicz > Acked-by: Michal Jastrzebski Applied to dpdk-next-crypto. Thanks, Pablo