NVMe over Fabrics transport requirements support

Sagi Grimberg sagi at grimberg.me
Wed Jun 24 15:25:18 EDT 2020


Hey Alex,

> Is it true that setting any value in addr_treq attribute of port in via 
> configfs
> 
> only affects displaying TREQ on discovery page and doesn't anyhow inflicts
> 
> "whether connections shall be made over a fabric secure channel"?
> 
> 
> I can't find much about whether RDMA(RoCE in particular) is secure
> 
> but for TCP TLS is must-do these days I think.
> 
> 
> Is this functionality planned to be implemented in near future?

There were some discussions around adding this. Currently there is
some infrastructure work that we need to do first to have a kernel
consumer utilize ktls (mostly revolves around the fact that both
ktls and nvme-tcp are socket consumers and implement sk upcalls).

I'm CC'ing Boris and Or who were very much involved with the
ktls implementation in Linux, they can maybe provide some more
input.



More information about the Linux-nvme mailing list