However, when this option is set, the plugin might actually use either AES-CTR or AES-GCM, depending on the situation:
The AES_CTR mode uses AES in two slightly different modes in different contexts. When encrypting tablespace pages (such as pages in InnoDB, XtraDB, and Aria tables), it uses AES in the Counter (CTR) mode. When encrypting temporary files (where the cipher text is allowed to be larger than the plain text), it uses AES in the authenticated Galois/Counter Mode (GCM).
After MDEV-18531, wolfSSL will be the new bundled TLS library in MariaDB 10.4.6 and later. According to cmake/ssl.cmake, wolfSSL supports AES-CTR, but not AES-GCM:
Since wolfSSL doesn't support AES-GCM, it looks looks like the plugin will use AES-CTR in the cases where it would usually use AES-GCM, if the TLS library were OpenSSL:
Do we need to test whether file_key_management_encryption_algorithm=AES_CTR will work properly with wolfSSL?
Will this difference support migrations where the original server used OpenSSL, and the new server used wolfSSL (or vice-versa)? Or is AES-GCM only used in cases where the files won't be needed beyond server restarts?
Attachments
Issue Links
relates to
MDEV-18531Use WolfSSL instead of YaSSL as "bundled" SSL
AES-CTR would work differently from OpenSSL, the unit test aes-t would fail due to different length of encrypted data compared to OpenSSL, and thus CTR is now disabled with WolfSSL, just as it was the case for YASSL
Vladislav Vaintroub
added a comment - - edited AES-CTR would work differently from OpenSSL, the unit test aes-t would fail due to different length of encrypted data compared to OpenSSL, and thus CTR is now disabled with WolfSSL, just as it was the case for YASSL
People
Vladislav Vaintroub
Geoff Montee (Inactive)
Votes:
0Vote for this issue
Watchers:
2Start watching this issue
Dates
Created:
Updated:
Resolved:
Git Integration
Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.
{"report":{"fcp":721.2000000476837,"ttfb":195.79999995231628,"pageVisibility":"visible","entityId":76229,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":1,"journeyId":"91486e15-15c8-44ee-bdb3-1f94914ac55b","navigationType":0,"readyForUser":777,"redirectCount":0,"resourceLoadedEnd":491.60000014305115,"resourceLoadedStart":203.20000004768372,"resourceTiming":[{"duration":4.099999904632568,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2bu7/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":203.20000004768372,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":203.20000004768372,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":207.29999995231628,"responseStart":0,"secureConnectionStart":0},{"duration":4,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2bu7/820016/12ta74/8679b4946efa1a0bb029a3a22206fb5d/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":203.40000009536743,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":203.40000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":207.40000009536743,"responseStart":0,"secureConnectionStart":0},{"duration":82.29999995231628,"initiatorType":"script","name":"https://jira.mariadb.org/s/fbf975c0cce4b1abf04784eeae9ba1f4-CDN/lu2bu7/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":203.60000014305115,"connectEnd":203.60000014305115,"connectStart":203.60000014305115,"domainLookupEnd":203.60000014305115,"domainLookupStart":203.60000014305115,"fetchStart":203.60000014305115,"redirectEnd":0,"redirectStart":0,"requestStart":210.40000009536743,"responseEnd":285.90000009536743,"responseStart":243.10000014305115,"secureConnectionStart":203.60000014305115},{"duration":102.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/099b33461394b8015fc36c0a4b96e19f-CDN/lu2bu7/820016/12ta74/8679b4946efa1a0bb029a3a22206fb5d/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":203.60000014305115,"connectEnd":203.60000014305115,"connectStart":203.60000014305115,"domainLookupEnd":203.60000014305115,"domainLookupStart":203.60000014305115,"fetchStart":203.60000014305115,"redirectEnd":0,"redirectStart":0,"requestStart":210.90000009536743,"responseEnd":306.10000014305115,"responseStart":239.90000009536743,"secureConnectionStart":203.60000014305115},{"duration":34.700000047683716,"initiatorType":"script","name":"https://jira.mariadb.org/s/94c15bff32baef80f4096a08aceae8bc-CDN/lu2bu7/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":203.70000004768372,"connectEnd":203.70000004768372,"connectStart":203.70000004768372,"domainLookupEnd":203.70000004768372,"domainLookupStart":203.70000004768372,"fetchStart":203.70000004768372,"redirectEnd":0,"redirectStart":0,"requestStart":211.5,"responseEnd":238.40000009536743,"responseStart":237.60000014305115,"secureConnectionStart":203.70000004768372},{"duration":36,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":203.79999995231628,"connectEnd":203.79999995231628,"connectStart":203.79999995231628,"domainLookupEnd":203.79999995231628,"domainLookupStart":203.79999995231628,"fetchStart":203.79999995231628,"redirectEnd":0,"redirectStart":0,"requestStart":212.29999995231628,"responseEnd":239.79999995231628,"responseStart":239.20000004768372,"secureConnectionStart":203.79999995231628},{"duration":35.200000047683716,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":203.90000009536743,"connectEnd":203.90000009536743,"connectStart":203.90000009536743,"domainLookupEnd":203.90000009536743,"domainLookupStart":203.90000009536743,"fetchStart":203.90000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":212.79999995231628,"responseEnd":239.10000014305115,"responseStart":238.5,"secureConnectionStart":203.90000009536743},{"duration":9,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2bu7/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":204,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":204,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":213,"responseStart":0,"secureConnectionStart":0},{"duration":10,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2bu7/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":204.20000004768372,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":204.20000004768372,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":214.20000004768372,"responseStart":0,"secureConnectionStart":0},{"duration":55.299999952316284,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":204.20000004768372,"connectEnd":204.20000004768372,"connectStart":204.20000004768372,"domainLookupEnd":204.20000004768372,"domainLookupStart":204.20000004768372,"fetchStart":204.20000004768372,"redirectEnd":0,"redirectStart":0,"requestStart":216.40000009536743,"responseEnd":259.5,"responseStart":258.7000000476837,"secureConnectionStart":204.20000004768372},{"duration":59.90000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/3339d87fa2538a859872f2df449bf8d0-CDN/lu2bu7/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":204.29999995231628,"connectEnd":204.29999995231628,"connectStart":204.29999995231628,"domainLookupEnd":204.29999995231628,"domainLookupStart":204.29999995231628,"fetchStart":204.29999995231628,"redirectEnd":0,"redirectStart":0,"requestStart":218.20000004768372,"responseEnd":264.2000000476837,"responseStart":263.60000014305115,"secureConnectionStart":204.29999995231628},{"duration":275.80000019073486,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":215.79999995231628,"connectEnd":215.79999995231628,"connectStart":215.79999995231628,"domainLookupEnd":215.79999995231628,"domainLookupStart":215.79999995231628,"fetchStart":215.79999995231628,"redirectEnd":0,"redirectStart":0,"requestStart":231,"responseEnd":491.60000014305115,"responseStart":488.2000000476837,"secureConnectionStart":215.79999995231628},{"duration":264.2000000476837,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":226.20000004768372,"connectEnd":226.20000004768372,"connectStart":226.20000004768372,"domainLookupEnd":226.20000004768372,"domainLookupStart":226.20000004768372,"fetchStart":226.20000004768372,"redirectEnd":0,"redirectStart":0,"requestStart":247.29999995231628,"responseEnd":490.40000009536743,"responseStart":485,"secureConnectionStart":226.20000004768372},{"duration":194.10000014305115,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":491.2999999523163,"connectEnd":491.2999999523163,"connectStart":491.2999999523163,"domainLookupEnd":491.2999999523163,"domainLookupStart":491.2999999523163,"fetchStart":491.2999999523163,"redirectEnd":0,"redirectStart":0,"requestStart":654.6000001430511,"responseEnd":685.4000000953674,"responseStart":684.6000001430511,"secureConnectionStart":491.2999999523163},{"duration":151.90000009536743,"initiatorType":"script","name":"https://www.google-analytics.com/analytics.js","startTime":698.7999999523163,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":698.7999999523163,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":850.7000000476837,"responseStart":0,"secureConnectionStart":0}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":53,"responseStart":196,"responseEnd":226,"domLoading":199,"domInteractive":822,"domContentLoadedEventStart":822,"domContentLoadedEventEnd":855,"domComplete":1151,"loadEventStart":1151,"loadEventEnd":1151,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":806.7000000476837},{"name":"bigPipe.sidebar-id.end","time":807.5},{"name":"bigPipe.activity-panel-pipe-id.start","time":807.7000000476837},{"name":"bigPipe.activity-panel-pipe-id.end","time":808.6000001430511},{"name":"activityTabFullyLoaded","time":869.1000001430511}],"measures":[],"correlationId":"847d3f10737e48","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":86,"dbReadsTimeInMs":9,"dbConnsTimeInMs":17,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}
AES-CTR would work differently from OpenSSL, the unit test aes-t would fail due to different length of encrypted data compared to OpenSSL, and thus CTR is now disabled with WolfSSL, just as it was the case for YASSL