Sign inSign up

intel/intel-qat-engine

Verified Publisher

By Intel Corporation

•Updated 2 months ago

Image
0

1.5K

intel/intel-qat-engine repository overview

⁠Introduction

Intel QuickAssist Technology (QAT) OpenSSL Engine is an OpenSSL Plug-In Engine that provides cryptographic acceleration for both hardware and optimized software using Intel QuickAssist Technology enabled Intel platforms. 

⁠How to Use This Image

⁠BIOS Setting

⁠Grub Settings

  • Intel IOMMU should be enabled and QAT VF to be bind to kernel. Follow the below steps.
⁠Ubuntu:
  • Edit the grub file: sudo vim /etc/default/grub
  • Modify GRUB_CMDLINE_LINUX to add intel_iommu=on vfio-pci.ids=8086:4941 (SPR)
  • Update grub: sudo update-grub
  • Reboot the system
⁠CentOS/Fedora:

⁠Docker Environment Setup

  • The environment must be set up to build and run containers. Certain packages will need to be loaded and configuration files created and/or updated, which can be system specific.
  • Install Docker following the steps in Docker Package Installation⁠.
  • Configure the proxy setting following Proxy settings⁠.

⁠Enable Intel® QAT Virtual Function (VF) Devices

  • Enable the VF devices using the following script:   sh   for i in `(lspci -D -d :4940 || lspci -D -d :4942) | awk '{print $1}'`; do echo 16 | sudo tee /sys/bus/pci/devices/$i/sriov_numvfs; done  

⁠Configure Services in the Host

  • Stop the Intree or OOT services if any running on the host:     sh   systemctl stop qat     sh   systemctl stop qat_service     sh   systemctl disable qat_service  
  • Bring the QAT device down:   sh   for i in `lspci -D -d :4940 | awk '{print $1}'`; do echo down > /sys/bus/pci/devices/$i/qat/state; done  
  • Set the correct service in the QAT devices:   sh   for i in `lspci -D -d :4940 | awk '{print $1}'`; do echo "sym;asym" > /sys/bus/pci/devices/$i/qat/cfg_services; done  
  • Bring the QAT device up:   sh   for i in `lspci -D -d :4940 | awk '{print $1}'`; do echo up > /sys/bus/pci/devices/$i/qat/state; done  
  • Check the status:   sh   for i in `lspci -D -d :4940 | awk '{print $1}'`; do cat /sys/bus/pci/devices/$i/qat/state; done  
  • Ensure the GID using the below command in host. The GID of the QAT group on the host should be same as GID of the docker Image. The QAT group of the host should be ‘1001’ :   sh   getent group qat | cut -d ':' -f 3  
  • Enable the VF devices with the previously mentioned script and set correct permissions:   sh   chown root:qat /dev/vfio/*     sh   chmod 660 /dev/vfio/*  

⁠Run Image

To run the Docker image, use the following command:

docker run -it --cap-add=IPC_LOCK --security-opt seccomp=unconfined --security-opt apparmor=unconfined $(for i in `ls /dev/vfio/*`; do echo --device $i; done) --cpuset-cpus <n cores> --env QAT_POLICY=1 --ulimit memlock=50000000:50000000 intel/intel-qat-engine:<tag_number> openssl speed  -provider qatprovider -provider default -elapsed -async_jobs 72 -multi <n> <algo>

Note: n is the number of processes.

⁠Sample Test Output

docker run -it --cap-add=IPC_LOCK --security-opt seccomp=unconfined --security-opt apparmor=unconfined $(for i in `ls /dev/vfio/*`; do echo --device $i; done) --cpuset-cpus 0-63 --env QAT_POLICY=1 --ulimit memlock=524288000:524288000 intel/intel-qat-engine:<tag_number>  openssl speed  -provider qatprovider -provider default -elapsed -async_jobs 72 -multi 64 rsa2048
version: 3.5.7
built on: Thu Jul 23 03:54:54 2026 UTC
options: bn(64,64)
compiler: gcc -fPIC -pthread -m64 -Wa,--noexecstack -Wall -O3 -DOPENSSL_USE_NODELETE -DL_ENDIAN -DOPENSSL_PIC -DOPENSSL_BUILDING_OPENSSL -DNDEBUG
CPUINFO: OPENSSL_ia32cap=0x7ffef3ffffebffff:0xfb417ffef3bfbfff:0x40601d30ffdd4432:0x00000001000e4000:0x0007000100000000
                   sign    verify    encrypt   decrypt   sign/s verify/s  encr./s  decr./s
rsa  2048 bits 0.000074s 0.000005s 0.000009s 0.000160s  13540.1 203929.3 106579.3   6238.6
                               keygen    encaps    decaps keygens/s  encaps/s  decaps/s
                    rsa2048 0.055922s 0.000016s 0.000251s      17.9   61781.2    3988.2
                               keygen     signs    verify keygens/s    sign/s  verify/s
                    rsa2048 0.055110s 0.000074s 0.000005s      18.1   13430.4  201675.5

Intel, Intel Atom, and Xeon are trademarks of Intel Corporation in the U.S. and/or other countries.

*Other names and brands may be claimed as the property of others.

Copyright © 2026, Intel Corporation. All rights reserved.

Tag summary

Content type

Image

Digest

sha256:012874ed2…

Size

216.1 MB

Last updated

2 months ago

docker pull intel/intel-qat-engine:2.2.0

This week's pulls

Pulls:

7

Sep 14 to Sep 20