From owner-freebsd-geom@FreeBSD.ORG Thu Jun 19 15:39:32 2008 Return-Path: Delivered-To: freebsd-geom@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id A697A1065684 for ; Thu, 19 Jun 2008 15:39:32 +0000 (UTC) (envelope-from fbsd06+XB=685016ce@mlists.homeunix.com) Received: from fallback-in1.mxes.net (fallback-out1.mxes.net [216.86.168.190]) by mx1.freebsd.org (Postfix) with ESMTP id 6BF878FC21 for ; Thu, 19 Jun 2008 15:39:32 +0000 (UTC) (envelope-from fbsd06+XB=685016ce@mlists.homeunix.com) Received: from mxout-03.mxes.net (mxout-03.mxes.net [216.86.168.178]) by fallback-in1.mxes.net (Postfix) with ESMTP id 39F9616421E for ; Thu, 19 Jun 2008 11:23:50 -0400 (EDT) Received: from gumby.homeunix.com. (unknown [87.81.140.128]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by smtp.mxes.net (Postfix) with ESMTP id AAD3E23E4AF for ; Thu, 19 Jun 2008 11:23:48 -0400 (EDT) Date: Thu, 19 Jun 2008 16:23:45 +0100 From: RW To: freebsd-geom@freebsd.org Message-ID: <20080619162345.7aaa94a3@gumby.homeunix.com.> In-Reply-To: <20080619142723.GA97597@voi.aagh.net> References: <20080618225407.1337ad03@gumby.homeunix.com.> <20080619142723.GA97597@voi.aagh.net> X-Mailer: Claws Mail 3.4.0 (GTK+ 2.12.10; i386-portbld-freebsd7.0) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Subject: Re: Is geli detectable? X-BeenThere: freebsd-geom@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: GEOM-specific discussions and implementations List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 19 Jun 2008 15:39:32 -0000 On Thu, 19 Jun 2008 15:27:23 +0100 Thomas Hurst wrote: > * Greg Rivers (gcr@tharned.org) wrote: > > You can prove this by running `geli dump > > ` when the provider is not attached (decrypted), or by > > otherwise inspecting the last sector. > > Yup, this is how the .eli devices magic into existance on boot/attach. > ... > Similarly I expect you could encrypt the metadata block itself, again > forgoing auto-detection in favour of manually mounting; geli devices are found at boot by looking for devices that end in .eli in fstab.