Managing Encryption and Certificates in Oracle® Solaris 11.2

Updated: September 2014

Cryptographic Framework and SPARC T-Series Servers

The Cryptographic Framework supplies the SPARC T-Series systems with cryptographic mechanisms, and optimizes some mechanisms for these servers. Three cryptographic mechanisms are optimized for data at rest and in motion: AES-CBC, AES-CFB128, and ARCFOUR. The DES cryptographic mechanism is optimized for OpenSSL, and, by optimizing arbitrary-precision arithmetic (bignum), so are RSA and DSA. Other optimizations include small packet performance for handshakes and data in motion.

    The following cryptographic mechanisms are available in this release:

  • AES-XTS – Used for data at rest

  • SHA-224SHA2 mechanism

  • AES-XCBC-MAC – Used for IPsec