Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 16 Sep 2020 21:06:03 +0100
From:      Steve O'Hara-Smith <steve@sohara.org>
To:        freebsd-questions@freebsd.org
Subject:   Re: move zfs geli encrypt mirror to unencrypted
Message-ID:  <20200916210603.3cf2f5c8215b39f552029c72@sohara.org>
In-Reply-To: <2cf11fa5-3e5c-1934-7af3-8b1aeb28eb79@beepc.ch>
References:  <66e2f2da-af22-766a-cc7a-78c29735e39f@beepc.ch> <20200916153611.abaaa06edad1738c9c4c381e@sohara.org> <2cf11fa5-3e5c-1934-7af3-8b1aeb28eb79@beepc.ch>

next in thread | previous in thread | raw e-mail | index | archive | help
On Wed, 16 Sep 2020 17:39:31 +0200
xpetrl <xpetrl@beepc.ch> wrote:

> >> We have a server with 4 disks, 2 zpool are zfs mirror:
> >>
> >> - base system unencrypted, partitions (da*p2)
> >> - data storage, geli encrypted, partitions (da*p4)
> >>
> >> We now want to "move" the data storage (encrypt) to unencrypted
> >> partition.
> > 
> > 	Do you still want the encrypted partitions ? If not the simplest
> > thing to do would be to detach the encrypted devices (daNp4.eli) one at
> > a time and attach the unencrypted device (daNp4) in its place, wait for
> > the resilver and repeat for the other devices in the zvol.
> > 
> 
> We don't need the encrypted partition anymore.
> 
> Your procedure is really convenient, thank you.
> 
> Do I have to take care about geli in some way?

	Disable whatever was running geli attach, it'll fail anyway when
the decrypt fails but disabling it is neater.

-- 
Steve O'Hara-Smith <steve@sohara.org>



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20200916210603.3cf2f5c8215b39f552029c72>