From nobody Sat Jun 27 14:51:34 2026 X-Original-To: dev-commits-doc-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4gnb8k4vgJz6jh61 for ; Sat, 27 Jun 2026 14:51:34 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR1" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4gnb8k3rKzz3bvD for ; Sat, 27 Jun 2026 14:51:34 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1782571894; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=k5E6SnQMOoUekwp8DP4oJB+o5AbrC2Iaocramtu73EQ=; b=w8g8HwHhbGGFyw/cxeWu73drTrzz3OawzRfB3rZqXe1OmUMI5uZGAanvgI2PL2HwTE59ij jS3+BAYNmVOsatxT1eh0Cv8+tEyhWRqDqKK7LtvsA04duVceth0Ae2oPm9KGUjz1prI/l+ XET5utW8v4BIrbV0p6iPQv4lb9FQ/Be4zwAYV9vbL2hgSZj+GF11BoLB2xAWIa+qoXIu+5 kOSPvI+Y6chJF07X+xxszMbOyjkIpM7fS6uz4Kbo48r92EN82A4ytJJZ7ullYoV0E0rlJZ WTNlMJDTWylQHAtWnqCTDIfgegqK2lmLrfnQTZ0OND/JgFDW4NscU6vF8XkXlA== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1782571894; a=rsa-sha256; cv=none; b=Itupe/+CZspLldsxwpxA2uDTh5NBANXkSGrdftTkKI3QdANNXxVXXqD0xr90gQL0MojhuM URjjeDB6fMuzabevEh+HNoRkUEpUjxoIUuEFdH6CNl4xIPhmmvE4xAx6+e38GtkCWH9kIv ALEag4smZR80qeuFonA0TVTGeJ+iVltF1CITtuwpa8TRPZOI4qNo3NQwNL2nXD984FAo5h sS6XkmGfcYILikJTMzaWVR30i3jiXyZGLUmQMvwXasm+26EBeThwP+CI+qkXPgBR6vOUC6 FY5yVVz2kPKhU8T1wRVvcQ5AK3MZKBdGHurSoqPVBeoIB/Ekw7DCJ8cUVC1A7A== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1782571894; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=k5E6SnQMOoUekwp8DP4oJB+o5AbrC2Iaocramtu73EQ=; b=VLbu1ROJz3oJ4OcOdqSop1rrFwk7RAR5SnEarXRc6/8RzQ+evaxlfut3kR/b9p3Occqapa qBClIPS7Duvje/engFbo/zomcWLD/FM36cDiHJTVU2U+ugn/Esq8719ki39hL4sGxQWzp7 bge1pK0Rvq2OsybVbqb7GuXvzYoOJAxakL0QTCPtYIQXegRrprFWnk6BQdzzSKHyMjguuA 8h1o770MvlGtNTddiTICXwTie4Kz2SWi6zhMNaGsrIrCLV5D312apYwR9R3aTSrp1MxRS5 i2hJh1lpPsODZ1y2bvMxNDH1rGypVFCH2dl7BKfLvCI/KlzmzUMMBxjPSpCBZQ== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4gnb8k2prjzD4d for ; Sat, 27 Jun 2026 14:51:34 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 20ea3 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Sat, 27 Jun 2026 14:51:34 +0000 To: doc-committers@FreeBSD.org, dev-commits-doc-all@FreeBSD.org From: Benedict Reuschling Subject: git: ee930e81a0 - main - handbook/disks: Update encrypted swap instructions for geli List-Id: Commit messages for all branches of the doc repository List-Archive: https://lists.freebsd.org/archives/dev-commits-doc-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-doc-all@freebsd.org Sender: owner-dev-commits-doc-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: bcr X-Git-Repository: doc X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: ee930e81a02548fe7a5881fdaf385754a3dff07d Auto-Submitted: auto-generated Date: Sat, 27 Jun 2026 14:51:34 +0000 Message-Id: <6a3fe376.20ea3.6623dfa5@gitrepo.freebsd.org> The branch main has been updated by bcr: URL: https://cgit.FreeBSD.org/doc/commit/?id=ee930e81a02548fe7a5881fdaf385754a3dff07d commit ee930e81a02548fe7a5881fdaf385754a3dff07d Author: Benedict Reuschling AuthorDate: 2026-06-27 14:16:39 +0000 Commit: Benedict Reuschling CommitDate: 2026-06-27 14:48:33 +0000 handbook/disks: Update encrypted swap instructions for geli Add instructions to initialize the geli swap device first. Also, be a bit clearer on the /etc/fstab line to add for geli. While here: fix a typo in the Camellia-CBC algorithm. PR: 282806 Reviewed by: carlavilla@ Event: Halifax Hackathon 202606 Location: Dalhousie CS Faculty building entrance hallway Differential Revision: https://reviews.freebsd.org/D57904 --- documentation/content/en/books/handbook/disks/_index.adoc | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/documentation/content/en/books/handbook/disks/_index.adoc b/documentation/content/en/books/handbook/disks/_index.adoc index db966c3f67..1a83ba8f98 100644 --- a/documentation/content/en/books/handbook/disks/_index.adoc +++ b/documentation/content/en/books/handbook/disks/_index.adoc @@ -1912,7 +1912,7 @@ This control utility adds some features and uses a different scheme for doing cr It provides the following features: * Utilizes the man:crypto[9] framework and automatically uses cryptographic hardware when it is available. -* Supports multiple cryptographic algorithms such as AES-XTS, AES-CBC, and Camellia-CBCAES. +* Supports multiple cryptographic algorithms such as AES-XTS, AES-CBC, and Camellia-CBC. * Allows the root partition to be encrypted. The passphrase used to access the encrypted root partition will be requested during system boot. * Allows the use of two independent keys. * It is fast as it performs simple sector-to-sector encryption. @@ -2078,7 +2078,14 @@ To encrypt the swap partition using man:gbde[8], add the `.bde` suffix to the sw /dev/ada0s1b.bde none swap sw 0 0 .... -To instead encrypt the swap partition using man:geli[8], use the `.eli` suffix: +To instead encrypt the swap partition using man:geli[8], initialize the device with a onetime key: + +[source,shell] +.... +# geom eli onetime -d /dev/ada0s1b +.... + +Afterwards, add a line for the device with the `.eli` suffix to [.filename]#/etc/fstab#: [.programlisting] ....