From sacadmin Wed Oct 19 21:25:13 2005
Received: from sunmail1brm.Central.Sun.COM (sunmail1brm.Central.Sun.COM [129.147.62.17])
	by sac.sfbay.sun.com (8.12.9+Sun/8.12.9) with ESMTP id j9K4PCIQ026949
	for <psarc@sac.eng.Sun.COM>; Wed, 19 Oct 2005 21:25:13 -0700 (PDT)
Received: from jurassic.eng.sun.com (jurassic.SFBay.Sun.COM [129.146.226.130])
	by sunmail1brm.Central.Sun.COM (8.11.7p1+Sun/8.11.7/ENSMAIL,v2.2) with ESMTP id j9K4P6B04985;
	Wed, 19 Oct 2005 22:25:07 -0600 (MDT)
Received: from sun.com (vpn-129-150-26-209.SFBay.Sun.COM [129.150.26.209])
	by jurassic.eng.sun.com (8.13.5+Sun/8.13.5) with ESMTP id j9K4P6TM694841;
	Wed, 19 Oct 2005 21:25:06 -0700 (PDT)
Message-ID: <43571C1B.2000403@sun.com>
Date: Wed, 19 Oct 2005 21:24:59 -0700
From: Sherri Shieh <Sherri.Shieh@sun.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.4.1) Gecko/20031008
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: psarc@sun.com
CC: gh-core@sun.com
Subject: New PSARC Materials Submitted: Greyhound (kernel SSL proxy) amendement
 (2005/625)
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Status: RO
Content-Length: 896

All,

Materials are now available for 2005/625:

-rw-r--r--   1 kais     sac-2     128664 Oct 19 15:46 
greyhound_amendment.pdf
-rw-r--r--   1 kais     sac-2      15488 Oct 19 16:45 
greyhound_amendment_20Q.txt

- Sherri

-- 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Sherri Shieh
Program Manager, System Architecture
Sun Microsystems, Inc.            
Email: Sherri.Shieh@sun.com
Phone: 650-786-5245/x85345
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



From sacadmin Wed Oct 26 09:41:04 2005
Received: from sunmail3.sfbay.sun.com (sunmail3.SFBay.Sun.COM [129.149.247.180])
	by sac.sfbay.sun.com (8.12.9+Sun/8.12.9) with ESMTP id j9QGf3IQ017597
	for <psarc@sac.eng.sun.com>; Wed, 26 Oct 2005 09:41:03 -0700 (PDT)
Received: from jurassic.eng.sun.com (jurassic.SFBay.Sun.COM [129.146.106.31])
	by sunmail3.sfbay.sun.com (8.11.7p1+Sun/8.11.7/ENSMAIL,v2.2) with ESMTP id j9QGf2120337;
	Wed, 26 Oct 2005 09:41:02 -0700 (PDT)
Received: from sun.com (sr1-umpk-04.SFBay.Sun.COM [129.146.11.160])
	by jurassic.eng.sun.com (8.13.5+Sun/8.13.5) with ESMTP id j9QGf1Kc751653;
	Wed, 26 Oct 2005 09:41:02 -0700 (PDT)
Message-ID: <435FB19D.60201@sun.com>
Date: Wed, 26 Oct 2005 09:41:01 -0700
From: Sherri Shieh <sherri.shieh@sun.com>
User-Agent: Mozilla/5.0 (X11; U; SunOS sun4u; en-US; rv:1.4) Gecko/20041214
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: psarc@sun.com
CC: Kais Belgaied <Kais.Belgaied@sun.com>
Subject: issues for 2005/625
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Status: RO
Content-Length: 344

All,

I've pasted the responses of 2005/625 into the issues file as well.

- Sherri

-- 


=========================================================
Sherri Shieh			Sun Microsystems, Inc.
Program Manager			Email: sherri.shieh@sun.com
Systems Architecture		Phone: 650-786-5245/x85245
===========================================================



From sacadmin Wed Oct 26 17:09:29 2005
Received: from sunmail3.sfbay.sun.com (sunmail3.SFBay.Sun.COM [129.149.247.180])
	by sac.sfbay.sun.com (8.12.9+Sun/8.12.9) with ESMTP id j9R09TIQ024607
	for <psarc@sac.eng.sun.com>; Wed, 26 Oct 2005 17:09:29 -0700 (PDT)
Received: from jurassic.eng.sun.com (jurassic.SFBay.Sun.COM [129.146.228.31])
	by sunmail3.sfbay.sun.com (8.11.7p1+Sun/8.11.7/ENSMAIL,v2.2) with ESMTP id j9R09S124808
	for <psarc@Sun.COM>; Wed, 26 Oct 2005 17:09:28 -0700 (PDT)
Received: from Sun.COM (sr1-umpk-04.SFBay.Sun.COM [129.146.11.160])
	by jurassic.eng.sun.com (8.13.5+Sun/8.13.5) with ESMTP id j9R09Sgv963748
	for <psarc@sun.com>; Wed, 26 Oct 2005 17:09:28 -0700 (PDT)
Message-ID: <43601AB8.9020004@Sun.COM>
Date: Wed, 26 Oct 2005 17:09:28 -0700
From: Kais Belgaied <Kais.Belgaied@Sun.COM>
Reply-To: Kais.Belgaied@Sun.COM
User-Agent: Mozilla/5.0 (X11; U; SunOS sun4u; en-US; rv:1.4) Gecko/20041214
X-Accept-Language: ar-eg, en-us, en, ar, ar-dz, ar-bh, ar-iq, ar-jo, ar-kw, ar-lb, ar-ly, ar-ma, ar-om, ar-qa, ar-sa, ar-sy, ar-tn, ar-ae, ar-ye
MIME-Version: 1.0
To: psarc@Sun.COM
Subject: Opinion for review, PSARC/2005/625 Greyhound (Kernel SSL Proxy) amendment
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Status: RO
Content-Length: 5250

Below is the opinion for PSARC/2005/625 - Greyhound (Kernel SSL Proxy) amendment

Please review by November 3rd 2005


 sun
   microsystems              Systems Architecture Committee
_________________________________________________________________

Subject:        Greyhound (Kernel SSL proxy) amendment


Submitted by:   Kais Belgaied et al.


File:           PSARC/2005/625/opinion.ascii


Date:           October 26th 2005


Committee:      James Carlson (opinion written by Kais Belgaied),
                Bill Sommerfeld, Ed Gould, Robert Berube.


Product Approval Committee:     Solaris PAC
                                solaris-pac@sun.com


1.  Summary

        This project supersedes PSARC/2002/557, and offers in-kernel
        SSL proxy in general, and not limited to HTTP, nor content
        cacheable by NL7C only.
        The project delivers hooks in the TCP/IP stack, sockfs and
        the streams framework to invoke the SSL proxy functionality.
        The internal SSL protocol implementation, and the configuration and
        administration model are taken unchanged from PSARC/2002/557.


2.  Decision & Precedence Information

        The project is approved as specified in reference [1].

        The project may be delivered as a patch.



3. Interfaces

The project exports the following interfaces.


    ___________________________________________________________________________
    |                           Interfaces Exported                           |
    +----------------------------+-----------------+--------------------------+
    | Interface Name             | Classification  | Comment                  |
    +----------------------------+-----------------+--------------------------+
    | so_kssl_endpt_type         | Project private | fields in the sonode_t   |
    | so_kssl_ent                |                 | private socket structure |
    | so_kssl_ctx                |                 |                          |
    +----------------------------+-----------------+--------------------------+
    | tcp_kssl_endpt_type        | Project private | fields in the tcp_t      |
    | tcp_kssl_ent               |                 | private TCP structure    |
    | tcp_kssl_ctx               |                 |                          |
    +----------------------------+-----------------+--------------------------+
    | T_SSL_PROXY_BIND_REQ       | Project Private | private TPI primitives   |
    | T_SSL_PROXY_CONN_IND       |                 |                          |
    +----------------------------+-----------------+--------------------------+
    | kssl_check_proxy()         | Project         | kernel SSL API entry     |
    | kssl_find_fallback()       | Private         | point private            |
    +----------------------------+-----------------+--------------------------+
    | kssl_input()               | Consolidation   | kernel SSL API entry     |
    | kssl_handle_record()       | Private         | point intended to continue
    | kssl_build_record()        |                 | be used by Chihuahua     |
    +----------------------------+-----------------+--------------------------+
    | so_tail                    | Consolidation   | extension to the         |
    | SO_TAIL                    | Private         | stroptions(9S)           |
    +----------------------------+-----------------+--------------------------+
    | sd_rputdatafunct           | Consolidation   | Hooks in the stream head |
    | sd_wputdatafunct           | Private         | structure                |
    +----------------------------+-----------------+--------------------------+
    | DBLK_COOKED                | Consolidation   | STREAMS data block flag  |
    |                            | Private         |                          |
    +----------------------------+-----------------+--------------------------+


4.  Opinion

        This is a short project, with very light overall architectural
        impact.
        Most of the discussion was about clarifying the changes from the
        original case.

        The discussion also brought up the comparison with the implementation
        of the SSL proxy as a streams module, as opposed to a collection of
        hooks in TCP, the stream head and sockfs. Although the two approaches
        are functionally equivalent, calling the SSL functions from hooks in
        the stream head, in the context of the sending and receiving
        application, allows better attributability of the CPU resources spent
        for the cryptographic operations in SSL.
        A member pointed out that other subsystems in Solaris, such as IPsec,
        face a similar issue of accounting for the CPU time spent
        in the kernel on behalf of user applications.


5.  Minority Opinion(s)

        none.


6.  Advisory Information

        none.


7.  Appendices

7.1.  Appendix A: Technical Changes Required

        none.


7.2.  Appendix B: Technical Changes Advised

        none.


7.3.  Appendix C: Reference Material

     Materials are relative to the case materials directory.


     1. Greyhound: Architecture of a Solaris Kernel SSL Proxy
        greyhound_amendment.pdf




From sac-owner Wed Feb  1 13:37:37 2006
Received: from jurassic.eng.sun.com (jurassic.SFBay.Sun.COM [129.146.68.36])
	by sac.sfbay.sun.com (8.12.9+Sun/8.12.9) with ESMTP id k11LbbIQ013891
	for <sac-review@sac.eng.sun.com>; Wed, 1 Feb 2006 13:37:37 -0800 (PST)
Received: from Sun.COM (sr1-umpk-20.SFBay.Sun.COM [129.146.11.208])
	by jurassic.eng.sun.com (8.13.5+Sun/8.13.5) with ESMTP id k11LbbN0241752
	for <sac-review@sac.eng>; Wed, 1 Feb 2006 13:37:37 -0800 (PST)
Message-ID: <43E12A21.5040703@Sun.COM>
Date: Wed, 01 Feb 2006 13:37:37 -0800
From: Kais Belgaied <Kais.Belgaied@Sun.COM>
Reply-To: Kais.Belgaied@Sun.COM
User-Agent: Mozilla/5.0 (X11; U; SunOS sun4u; en-US; rv:1.4) Gecko/20041214
X-Accept-Language: ar-eg, en-us, en, ar, ar-dz, ar-bh, ar-iq, ar-jo, ar-kw, ar-lb, ar-ly, ar-ma, ar-om, ar-qa, ar-sa, ar-sy, ar-tn, ar-ae, ar-ye
MIME-Version: 1.0
To: sac-review@sac.eng.sun.com
Subject: Opinion for SAC review PSARC/2005/625 Greyhound (SSL kernel proxy)
 amendment
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Status: RO
Content-Length: 5213

The attached opinion is ready for SAC review. Comments due by 02/08/2006


	Kais.


 sun
   microsystems              Systems Architecture Committee
_________________________________________________________________

Subject:        Greyhound (Kernel SSL proxy) amendment


Submitted by:   Kais Belgaied et al.


File:           PSARC/2005/625/opinion.ascii


Date:           October 26th 2005


Committee:      James Carlson (opinion written by Kais Belgaied),
                Bill Sommerfeld, Ed Gould, Robert Berube.


Product Approval Committee:     Solaris PAC
                                solaris-pac@sun.com


1.  Summary

        This project supersedes PSARC/2002/557, and offers in-kernel
        SSL proxy in general, and not limited to HTTP, nor content
        cacheable by NL7C only.
        The project delivers hooks in the TCP/IP stack, sockfs and
        the streams framework to invoke the SSL proxy functionality.
        The internal SSL protocol implementation, and the configuration and
        administration model are taken unchanged from PSARC/2002/557.


2.  Decision & Precedence Information

        The project is approved as specified in reference [1].

        The project may be delivered as a patch.



3. Interfaces

The project exports the following interfaces.


    ___________________________________________________________________________
    |                           Interfaces Exported                           |
    +----------------------------+-----------------+--------------------------+
    | Interface Name             | Classification  | Comment                  |
    +----------------------------+-----------------+--------------------------+
    | so_kssl_endpt_type         | Project private | fields in the sonode_t   |
    | so_kssl_ent                |                 | private socket structure |
    | so_kssl_ctx                |                 |                          |
    +----------------------------+-----------------+--------------------------+
    | tcp_kssl_endpt_type        | Project private | fields in the tcp_t      |
    | tcp_kssl_ent               |                 | private TCP structure    |
    | tcp_kssl_ctx               |                 |                          |
    +----------------------------+-----------------+--------------------------+
    | T_SSL_PROXY_BIND_REQ       | Project Private | private TPI primitives   |
    | T_SSL_PROXY_CONN_IND       |                 |                          |
    +----------------------------+-----------------+--------------------------+
    | kssl_check_proxy()         | Project         | kernel SSL API entry     |
    | kssl_find_fallback()       | Private         | point private            |
    +----------------------------+-----------------+--------------------------+
    | kssl_input()               | Consolidation   | kernel SSL API entry     |
    | kssl_handle_record()       | Private         | point intended to continue
    | kssl_build_record()        |                 | be used by Chihuahua     |
    +----------------------------+-----------------+--------------------------+
    | so_tail                    | Consolidation   | extension to the         |
    | SO_TAIL                    | Private         | stroptions(9S)           |
    +----------------------------+-----------------+--------------------------+
    | sd_rputdatafunct           | Consolidation   | Hooks in the stream head |
    | sd_wputdatafunct           | Private         | structure                |
    +----------------------------+-----------------+--------------------------+
    | DBLK_COOKED                | Consolidation   | STREAMS data block flag  |
    |                            | Private         |                          |
    +----------------------------+-----------------+--------------------------+


4.  Opinion

        This is a short project, with very light overall architectural
        impact.
        Most of the discussion was about clarifying the changes from the
        original case.

        The discussion also brought up the comparison with the implementation
        of the SSL proxy as a streams module, as opposed to a collection of
        hooks in TCP, the stream head and sockfs. Although the two approaches
        are functionally equivalent, calling the SSL functions from hooks in
        the stream head, in the context of the sending and receiving
        application, allows better attributability of the CPU resources spent
        for the cryptographic operations in SSL.
        A member pointed out that other subsystems in Solaris, such as IPsec,
        face a similar issue of accounting for the CPU time spent
        in the kernel on behalf of user applications.


5.  Minority Opinion(s)

        none.


6.  Advisory Information

        none.


7.  Appendices

7.1.  Appendix A: Technical Changes Required

        none.


7.2.  Appendix B: Technical Changes Advised

        none.


7.3.  Appendix C: Reference Material

     Materials are relative to the case materials directory.


     1. Greyhound: Architecture of a Solaris Kernel SSL Proxy
        greyhound_amendment.pdf


From sac-owner Fri Feb 10 16:27:46 2006
Received: from jurassic.eng.sun.com (jurassic.SFBay.Sun.COM [129.146.68.36])
	by sac.sfbay.sun.com (8.12.9+Sun/8.12.9) with ESMTP id k1B0RkIQ018217
	for <sac-opinion@sac.eng.sun.com>; Fri, 10 Feb 2006 16:27:46 -0800 (PST)
Received: from Sun.COM (sr1-umpk-20.SFBay.Sun.COM [129.146.11.208])
	by jurassic.eng.sun.com (8.13.5+Sun/8.13.5) with ESMTP id k1B0Rk0a652072;
	Fri, 10 Feb 2006 16:27:46 -0800 (PST)
Message-ID: <43ED2F81.8030606@Sun.COM>
Date: Fri, 10 Feb 2006 16:27:45 -0800
From: Kais Belgaied <Kais.Belgaied@Sun.COM>
Reply-To: Kais.Belgaied@Sun.COM
User-Agent: Mozilla/5.0 (X11; U; SunOS sun4u; en-US; rv:1.4) Gecko/20041214
X-Accept-Language: ar-eg, en-us, en, ar, ar-dz, ar-bh, ar-iq, ar-jo, ar-kw, ar-lb, ar-ly, ar-ma, ar-om, ar-qa, ar-sa, ar-sy, ar-tn, ar-ae, ar-ye
MIME-Version: 1.0
To: sac-opinion@sac.eng.sun.com
CC: solaris-pac-opinion@Sun.COM
Subject: Opinion for archiving, PSARC/2005/625 Greyhound (SSL kernel proxy)
 amendment
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Status: RO
Content-Length: 5129

 sun
   microsystems              Systems Architecture Committee
_________________________________________________________________

Subject:        Greyhound (Kernel SSL proxy) amendment


Submitted by:   Kais Belgaied et al.


File:           PSARC/2005/625/opinion.ascii


Date:           October 26th 2005


Committee:      James Carlson (opinion written by Kais Belgaied),
                Bill Sommerfeld, Ed Gould, Robert Berube.


Product Approval Committee:     Solaris PAC
                                solaris-pac@sun.com


1.  Summary

        This project supersedes PSARC/2002/557, and offers in-kernel
        SSL proxy in general, and not limited to HTTP, nor content
        cacheable by NL7C only.
        The project delivers hooks in the TCP/IP stack, sockfs and
        the streams framework to invoke the SSL proxy functionality.
        The internal SSL protocol implementation, and the configuration and
        administration model are taken unchanged from PSARC/2002/557.


2.  Decision & Precedence Information

        The project is approved as specified in reference [1].

        The project may be delivered as a patch.



3. Interfaces

The project exports the following interfaces.


    ___________________________________________________________________________
    |                           Interfaces Exported                           |
    +----------------------------+-----------------+--------------------------+
    | Interface Name             | Classification  | Comment                  |
    +----------------------------+-----------------+--------------------------+
    | so_kssl_endpt_type         | Project private | fields in the sonode_t   |
    | so_kssl_ent                |                 | private socket structure |
    | so_kssl_ctx                |                 |                          |
    +----------------------------+-----------------+--------------------------+
    | tcp_kssl_endpt_type        | Project private | fields in the tcp_t      |
    | tcp_kssl_ent               |                 | private TCP structure    |
    | tcp_kssl_ctx               |                 |                          |
    +----------------------------+-----------------+--------------------------+
    | T_SSL_PROXY_BIND_REQ       | Project Private | private TPI primitives   |
    | T_SSL_PROXY_CONN_IND       |                 |                          |
    +----------------------------+-----------------+--------------------------+
    | kssl_check_proxy()         | Project         | kernel SSL API entry     |
    | kssl_find_fallback()       | Private         | point private            |
    +----------------------------+-----------------+--------------------------+
    | kssl_input()               | Consolidation   | kernel SSL API entry     |
    | kssl_handle_record()       | Private         | point intended to continue
    | kssl_build_record()        |                 | be used by Chihuahua     |
    +----------------------------+-----------------+--------------------------+
    | so_tail                    | Consolidation   | extension to the         |
    | SO_TAIL                    | Private         | stroptions(9S)           |
    +----------------------------+-----------------+--------------------------+
    | sd_rputdatafunct           | Consolidation   | Hooks in the stream head |
    | sd_wputdatafunct           | Private         | structure                |
    +----------------------------+-----------------+--------------------------+
    | DBLK_COOKED                | Consolidation   | STREAMS data block flag  |
    |                            | Private         |                          |
    +----------------------------+-----------------+--------------------------+


4.  Opinion

        This is a short project, with very light overall architectural
        impact.
        Most of the discussion was about clarifying the changes from the
        original case.

        The discussion also brought up the comparison with the implementation
        of the SSL proxy as a streams module, as opposed to a collection of
        hooks in TCP, the stream head and sockfs. Although the two approaches
        are functionally equivalent, calling the SSL functions from hooks in
        the stream head, in the context of the sending and receiving
        application, allows better attributability of the CPU resources spent
        for the cryptographic operations in SSL.
        A member pointed out that other subsystems in Solaris, such as IPsec,
        face a similar issue of accounting for the CPU time spent
        in the kernel on behalf of user applications.


5.  Minority Opinion(s)

        none.


6.  Advisory Information

        none.


7.  Appendices

7.1.  Appendix A: Technical Changes Required

        none.


7.2.  Appendix B: Technical Changes Advised

        none.


7.3.  Appendix C: Reference Material

     Materials are relative to the case materials directory.


     1. Greyhound: Architecture of a Solaris Kernel SSL Proxy
        greyhound_amendment.pdf


