• Stefan Metzmacher's avatar
    cifs: don't try to use rdma offload on encrypted connections · 3891f6c7
    Stefan Metzmacher authored
    The aim of using encryption on a connection is to keep
    the data confidential, so we must not use plaintext rdma offload
    for that data!
    
    It seems that current windows servers and ksmbd would allow
    this, but that's no reason to expose the users data in plaintext!
    And servers hopefully reject this in future.
    
    Note modern windows servers support signed or encrypted offload,
    see MS-SMB2 2.2.3.1.6 SMB2_RDMA_TRANSFORM_CAPABILITIES, but we don't
    support that yet.
    Signed-off-by: default avatarStefan Metzmacher <metze@samba.org>
    Cc: Steve French <smfrench@gmail.com>
    Cc: Tom Talpey <tom@talpey.com>
    Cc: Long Li <longli@microsoft.com>
    Cc: Namjae Jeon <linkinjeon@kernel.org>
    Cc: David Howells <dhowells@redhat.com>
    Cc: linux-cifs@vger.kernel.org
    Cc: stable@vger.kernel.org
    Signed-off-by: default avatarSteve French <stfrench@microsoft.com>
    3891f6c7
smb2pdu.c 159 KB