Kane Huang



I have an query regarding AESNI-SHA1 "stitched" implementations. In the stitched implement such as aesni_128_cbc_hmac_sha1_cipher, i saw the code compute MAC on cleartext then encrypt, I thought this mode is used for SSL and SSH. Is there any stitched implement support for Encrypt then Authenticate (EtA) mode, which encrypt the cleartext, then compute the MAC on the ciphertext?


