OpenSolaris has a kernel level SSL server proxy (KSSL) that
can be used for improved SSL performance on the server side.
It can be configured as a proxy for a non-SSL server
(e.g. web servers like Apache and Sun web server) to communicate
with a SSL client.
There is an ongoing effort to add new features to KSSL.
This project provides a place for that ongoing effort.
Possible initial enhancements include:
- * Debugging tools and scripts (see KSSL debugging suite)
- * Add IPv6 support
- * Add support for TLS 1.1, and TLS 1.2
- * Performance optimizations
- * Add support for client authentication
- * Add support for ECC cipher suites
If you would like to be involved with this project, the best way to get started is to join the project development mailing list. If there is something in particular you are looking for, please feel free to ask.
This KSSL presentation offers an overview of KSSL and goes in to the design details.
on 2009/10/26 12:15