From owner-freebsd-questions@freebsd.org Wed Sep 16 20:06:14 2020 Return-Path: Delivered-To: freebsd-questions@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 2A2183F0021 for ; Wed, 16 Sep 2020 20:06:14 +0000 (UTC) (envelope-from 4250.82.1d4c4000233af60.560706e2dd84b64ad12b6a15536d902a@email-od.com) Received: from s1-b0c6.socketlabs.email-od.com (s1-b0c6.socketlabs.email-od.com [142.0.176.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 4BsB1c4mV4z4Cyj for ; Wed, 16 Sep 2020 20:06:12 +0000 (UTC) (envelope-from 4250.82.1d4c4000233af60.560706e2dd84b64ad12b6a15536d902a@email-od.com) DKIM-Signature: v=1; a=rsa-sha256; d=email-od.com;i=@email-od.com;s=dkim; c=relaxed/relaxed; q=dns/txt; t=1600286773; x=1602878773; h=content-transfer-encoding:content-type:mime-version:references:in-reply-to:message-id:subject:to:from:date:x-thread-info; bh=9/Fa1wHh8i14l2mKuSCUkH575Nl08rhe6qU8AJ5hB0M=; b=uoT8B9tbvFvX81s7EqaDXwZjy2Zvj2NkUBc7MlCZ0ATen8h9dSpbMDhQfRhKAwx5TopQ1NqvMiJoJOMi4/yiyJOYti60s6Eymso4dzhH5vUJPcc8gonUoIqj9i6l2/ChN7V1vfwsmDiVqUZg1GAoFaO7DDZJLQm456wSvob+qD8= X-Thread-Info: NDI1MC45Mi4xZDRjNDAwMDIzM2FmNjAuZnJlZWJzZC1xdWVzdGlvbnM9ZnJlZWJzZC5vcmc= Received: from r1.us-east-1.aws.in.socketlabs.com (r1.us-east-1.aws.in.socketlabs.com [142.0.191.1]) by mxsg2.email-od.com with ESMTP(version=Tls12 cipher=Aes256 bits=256); Wed, 16 Sep 2020 16:06:05 -0400 Received: from smtp.lan.sohara.org (EMTPY [185.202.17.215]) by r1.us-east-1.aws.in.socketlabs.com with ESMTP(version=Tls12 cipher=Aes256 bits=256); Wed, 16 Sep 2020 16:06:05 -0400 Received: from [192.168.63.1] (helo=steve.lan.sohara.org) by smtp.lan.sohara.org with smtp (Exim 4.94 (FreeBSD)) (envelope-from ) id 1kIdgq-000JLk-0R for freebsd-questions@freebsd.org; Wed, 16 Sep 2020 21:06:04 +0100 Date: Wed, 16 Sep 2020 21:06:03 +0100 From: Steve O'Hara-Smith To: freebsd-questions@freebsd.org Subject: Re: move zfs geli encrypt mirror to unencrypted Message-Id: <20200916210603.3cf2f5c8215b39f552029c72@sohara.org> In-Reply-To: <2cf11fa5-3e5c-1934-7af3-8b1aeb28eb79@beepc.ch> References: <66e2f2da-af22-766a-cc7a-78c29735e39f@beepc.ch> <20200916153611.abaaa06edad1738c9c4c381e@sohara.org> <2cf11fa5-3e5c-1934-7af3-8b1aeb28eb79@beepc.ch> X-Mailer: Sylpheed 3.7.0 (GTK+ 2.24.32; amd64-portbld-freebsd12.0) X-Clacks-Overhead: "GNU Terry Pratchett" Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-Rspamd-Queue-Id: 4BsB1c4mV4z4Cyj X-Spamd-Bar: - Authentication-Results: mx1.freebsd.org; dkim=pass header.d=email-od.com header.s=dkim header.b=uoT8B9tb; dmarc=none; spf=pass (mx1.freebsd.org: domain of 4250.82.1d4c4000233af60.560706e2dd84b64ad12b6a15536d902a@email-od.com designates 142.0.176.198 as permitted sender) smtp.mailfrom=4250.82.1d4c4000233af60.560706e2dd84b64ad12b6a15536d902a@email-od.com X-Spamd-Result: default: False [-1.96 / 15.00]; MID_RHS_MATCH_FROM(0.00)[]; ARC_NA(0.00)[]; R_DKIM_ALLOW(-0.20)[email-od.com:s=dkim]; NEURAL_HAM_MEDIUM(-0.99)[-0.992]; FROM_HAS_DN(0.00)[]; RWL_MAILSPIKE_GOOD(0.00)[142.0.176.198:from]; MV_CASE(0.50)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; MIME_GOOD(-0.10)[text/plain]; TO_DN_NONE(0.00)[]; DMARC_NA(0.00)[sohara.org]; RCPT_COUNT_ONE(0.00)[1]; NEURAL_HAM_LONG(-1.02)[-1.019]; RCVD_COUNT_THREE(0.00)[4]; R_SPF_ALLOW(-0.20)[+ip4:142.0.176.0/20]; DKIM_TRACE(0.00)[email-od.com:+]; NEURAL_HAM_SHORT(-0.25)[-0.249]; FORGED_SENDER(0.30)[steve@sohara.org,4250.82.1d4c4000233af60.560706e2dd84b64ad12b6a15536d902a@email-od.com]; MIME_TRACE(0.00)[0:+]; RCVD_TLS_LAST(0.00)[]; ASN(0.00)[asn:7381, ipnet:142.0.176.0/22, country:US]; FROM_NEQ_ENVFROM(0.00)[steve@sohara.org,4250.82.1d4c4000233af60.560706e2dd84b64ad12b6a15536d902a@email-od.com]; MAILMAN_DEST(0.00)[freebsd-questions] X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.33 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 16 Sep 2020 20:06:14 -0000 On Wed, 16 Sep 2020 17:39:31 +0200 xpetrl wrote: > >> We have a server with 4 disks, 2 zpool are zfs mirror: > >> > >> - base system unencrypted, partitions (da*p2) > >> - data storage, geli encrypted, partitions (da*p4) > >> > >> We now want to "move" the data storage (encrypt) to unencrypted > >> partition. > > > > Do you still want the encrypted partitions ? If not the simplest > > thing to do would be to detach the encrypted devices (daNp4.eli) one at > > a time and attach the unencrypted device (daNp4) in its place, wait for > > the resilver and repeat for the other devices in the zvol. > > > > We don't need the encrypted partition anymore. > > Your procedure is really convenient, thank you. > > Do I have to take care about geli in some way? Disable whatever was running geli attach, it'll fail anyway when the decrypt fails but disabling it is neater. -- Steve O'Hara-Smith