QAT_HW Algorithms list, its supported platforms and default behaviour
April 10, 2026 ยท View on GitHub
| QAT_HW Algorithms | v1.7 | v1.8 | v2.x | qatlib(intree) |
|---|---|---|---|---|
| RSA Key size < 2048 | ** | ** | ** | ** |
| RSA Key size >= 2048 <= 4096 | * | * | * | * |
| RSA Key size 8192 | * | * | ||
| ECDSA Curves with bitlen < 256 | ** | ** | ** | ** |
| ECDSA Curves with bitlen >= 256 | * | * | * | * |
| ECDH Curves with bitlen < 256 | ** | ** | ** | ** |
| ECDH Curves with bitlen >= 256 | * | * | * | * |
| ECDH X25519 & X448(ECX) | * | * | * | * |
| DSA | ** | ** | ** | ** |
| DH key size < 8192 | ** | ** | ** | ** |
| DH key size >=8192 | ** | ** | ||
| HKDF | *** | *** | *** | *** |
| PRF | * | * | * | * |
| AES-128-GCM | ** | ** | ** | ** |
| AES-256-GCM | *** | *** | *** | *** |
| AES-128-CCM | ** | ** | ** | ** |
| AES-192-CCM | ** | ** | ||
| AES-256-CCM | * | * | ||
| AES128_CBC_HMAC_SHA1 | ** | ** | ** | ** |
| AES256_CBC_HMAC_SHA1 | ** | ** | ** | ** |
| AES128_CBC_HMAC_SHA256 | ** | ** | ** | ** |
| AES256_CBC_HMAC_SHA256 | * | * | * | * |
| SHA3-224 | ** | ** | ** | |
| SHA3-256/384/512 | *** | *** | *** | |
| ChachaPoly | *** | *** | *** | |
| SM4-CBC | # | # | ||
| SM3 | *** | *** | ||
| SM2 | *** | *** |
* Enabled in the default build of qatengine for the specified platforms when --with-qat_hw_dir is provided in qatengine/qatprovider build configure.
** Insecure algorithms which are disabled by default in QAT_HW driver and qatengine/qatprovider. Can be enabled using configure flag --enable-qat_insecure_algorithms. Driver will also needs to be built with the flag ./configure --enable-legacy-algorithms to enable these algorithms at driver.
*** Algorithms disabled by default as those are experimental.
# Disabled by default as it is specific to Tongsuo and not applicable to OpenSSL. To be enabled when qatengine is built with Tongsuo.
Please refer config_options on details about algorithm enable/disable flags.