[pfx] Re: OpenSSL 3.5.x TLS handshake overhead on AL2023 vs AL2 (OpenSSL 1.0.2) — any interest in AWS-LC as an alterna tive TLS backend?

Wietse Venema via Postfix-users <[email protected]>
Newsgroups gmane.mail.postfix.user
Message-ID <[email protected]>
RM via Postfix-users:
> Hi Wietse,
> 
>   Thanks for confirming - that answers the data_directory question clearly,
>   appreciate it we'll build the rollout around that rather than trying
>   to relocate it.

My advice: better to work with the system than against it.

>   Circling back to the main question from the original message, since I
>   don't think it got addressed yet: has AWS-LC come up before as an
>   alternative TLS backend for Postfix, the way HAProxy supports building
>   against it? We measured a reproducible ~7-8x slower STARTTLS handshake
>   under OpenSSL 3.5.7 vs OpenSSL 1.0.2k on otherwise identical hosts/config
>   (numbers in the original message below), with the gap accelerating further
>   under concurrent load. Mainly curious whether this is a known/discussed
>   tradeoff of the 3.x provider architecture, or whether it's specific to our
>   setup somehow.

I am not aware of any reports that Postfix with OpenSSL 3.x performs
significantly slower than Postfix with OpenSSL 1.x.

However, my advice to work with the system applies very much to
Postfix/TLS configuration: don't override well-engineered default
settings unless there are really compelling reasons.

	Wietse
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.