Intel QuickAssist Technology (QAT) OpenSSL Engine is an OpenSSL Plug-In Engine that provides cryptographic acceleration for both hardware and optimized software using Intel QuickAssist Technology enabled Intel platforms.
sudo vim /etc/default/grubGRUB_CMDLINE_LINUX to add intel_iommu=on vfio-pci.ids=8086:4941 (SPR)sudo update-grubUpdate the kernel: grubby --update-kernel=/boot/vmlinuz-$(uname -r) --remove-args="intel_iommu=on" --args="intel_iommu=off vfio-pci.ids=8086:4941"
Reboot the system
Ensure VT-d and SRIOV are enabled in the host. The steps can be referred from the link [Configuring the host operating system with SR-IOV IOMMU](https://intel.github.io/quickassist/AppNotes/Containers/setup.html#configuring-the-host-operating-s…
sh for i in `(lspci -D -d :4940 || lspci -D -d :4942) | awk '{print $1}'`; do echo 16 | sudo tee /sys/bus/pci/devices/$i/sriov_numvfs; done sh systemctl stop qat
sh systemctl stop qat_service
sh systemctl disable qat_service sh for i in `lspci -D -d :4940 | awk '{print $1}'`; do echo down > /sys/bus/pci/devices/$i/qat/state; done sh for i in `lspci -D -d :4940 | awk '{print $1}'`; do echo "sym;asym" > /sys/bus/pci/devices/$i/qat/cfg_services; done sh for i in `lspci -D -d :4940 | awk '{print $1}'`; do echo up > /sys/bus/pci/devices/$i/qat/state; done sh for i in `lspci -D -d :4940 | awk '{print $1}'`; do cat /sys/bus/pci/devices/$i/qat/state; done sh getent group qat | cut -d ':' -f 3 sh chown root:qat /dev/vfio/*
sh chmod 660 /dev/vfio/* To run the Docker image, use the following command:
Server command: docker run --rm -it --cpuset-cpus <n cores> --cap-add=IPC_LOCK --security-opt seccomp=unconfined --security-opt apparmor=unconfined $(for i in `ls /dev/vfio/*`; do echo --device $i; done) --env QAT_POLICY=1 --ulimit memlock=50000000:50000000 -v /usr/local/etc/haproxy/:/usr/local/etc/haproxy/ -d -p 8080:8080 intel/intel-qat-haproxy:<tag_number> haproxy -f /usr/local/etc/haproxy/haproxy.cfg
Client command: openssl s_time -connect <server_ip>:8080 -cipher AES128-SHA256 -www /20b-file.html -time 5
Note: n is the number of thread. 8080 port to be used for starting the haproxy service. HAproxy config file mounted from the host to the container using -v /usr/local/etc/haproxy/haproxy.cfg.
Refer haproxy.cfg sample configuration with QAT Enabled
Intel, Intel Atom, and Xeon are trademarks of Intel Corporation in the U.S. and/or other countries.
*Other names and brands may be claimed as the property of others.
Copyright © 2026, Intel Corporation. All rights reserved.
Content type
Image
Digest
sha256:4a6b8c6b0…
Size
240.5 MB
Last updated
2 months ago
docker pull intel/intel-qat-haproxy:2.2.0Pulls:
4
Sep 14 to Sep 20