Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 10 Mar 2012 11:03:34 -0500
From:      "Matthew X. Economou" <xenophon@irtnog.org>
To:        <freebsd-stable@freebsd.org>
Subject:   RE: FreeBSD root on a geli-encrypted ZFS pool
Message-ID:  <BABF8C57A778F04791343E5601659908236BDC@cinip100ntsbs.irtnog.net>
In-Reply-To: <20120309152253.17a108c2@fabiankeil.de>
References:  <BABF8C57A778F04791343E5601659908236BD9@cinip100ntsbs.irtnog.net><20120307174850.746a6b0a@fabiankeil.de><BABF8C57A778F04791343E5601659908236BDA@cinip100ntsbs.irtnog.net> <20120309152253.17a108c2@fabiankeil.de>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Fabian Keil writes:

> In my opinion protecting ZFS's default checksums (which cover
> non-metadata as well) with GEOM_ELI is sufficient. I don't see
> what advantage additionally enabling GEOM_ELI's integrity
> verification offers.

I follow you now.  You may be right about the extra integrity checking
being redundant with ZFS. 

> Anyway, it's a test without file system so the ZFS overhead isn't
> measured. I wasn't entirely clear about it, but my assumption was
> that the ZFS overhead might be big enough to make the difference
> between HMAC/MD5 and HMAC/SHA256 a lot less significant.

Got it.  That also makes sense.  I'll put this on my to-test list. 

> I'm currently using sector sizes between 512 and 8192 so I'm not
> actually expecting technical problems, it's just not clear to me
> how much the sector size matters and if 4096 is actually the best
> value when using ZFS.

The geli(8) manual page claims that larger sector sizes lower the
overhead of GEOM_ELI keying initialization and encryption/decryption
steps by requiring fewer of these compute-intensive setup operations
per block.  You can think of it in terms of networking, where it makes
sense to re-use a TCP connection for multiple HTTP requests, because
for small HTTP requests, the bandwidth and latency caused by the TCP
three-way handshake overshadows the actual data transfer.

-- 
I FIGHT FOR THE USERS


[-- Attachment #2 --]
0	*H
010
	`He0	*H
00
'J0
	*H
0F10
	&,dnet10
	&,dirtnog10Uirtnog-root-ca0
120121220200Z
120918223956Z010
	&,dnet10
	&,dirtnog10U
MyBusiness10UUsers10USBSUsers10UMatthew X. Economou1"0 	*H
	xenophon@irtnog.org00
	*H
0ywxxv-4物.4aO@25NiC{
& jѩm'w♛
%jm}	dxG"WdR	Ԕ
&%'N
?
Z400	+7
User0)U%"0 
+7
++0U0D	*H
	7050*H
0*H
0+0
*H
0CU<0:#
+7xenophon@irtnog.netxenophon@irtnog.org0U)}.o]g^-0U#0m9{D&P70?U6020.*&ldap:///CN=irtnog-root-ca,CN=cinip100ntsbs,CN=CDP,CN=Public%20Key%20Services,CN=Services,CN=Configuration,DC=irtnog,DC=net?certificateRevocationList?base?objectClass=cRLDistributionPoint=http://cinip100ntsbs.irtnog.net/CertEnroll/irtnog-root-ca.crl(http://web.irtnog.org/irtnog-root-ca.crl0[+M0I0+0ldap:///CN=irtnog-root-ca,CN=AIA,CN=Public%20Key%20Services,CN=Services,CN=Configuration,DC=irtnog,DC=net?cACertificate?base?objectClass=certificationAuthority0b+0Vhttp://cinip100ntsbs.irtnog.net/CertEnroll/cinip100ntsbs.irtnog.net_irtnog-root-ca.crt04+0(http://web.irtnog.org/irtnog-root-ca.crt0
	*H
Ghưn< E5Re9!{*VFm0f?_;Rg*:Y؞'֑T\Jh	#Œu.FXdnS.[!x^Y1ey`MS1h-13F*-);ȖAsD8K2ZǮ)w*S׏M~c	gAX9ᕉx2Dkb큋`:hWRE0
eX`Tb*a |]G2[5J+ਁC1
FkB6_ʝ(J/wYl}C7aoY헀G	tJnP/qgR|Ŧk]TIyu͸.P)[ZWZJu@5t\:\k`U!Iy/H|vQ\s,;mepm3
 7p^l|e͠2tM@4Gm0T0<	Du@CQ(ĤE0
	*H
0F10
	&,dnet10
	&,dirtnog10Uirtnog-root-ca0
070918223246Z
120918223956Z0F10
	&,dnet10
	&,dirtnog10Uirtnog-root-ca0"0
	*H
0
:~.*S ӯr햝	ًjoףZ >>@"L&!,,UAo8-Eh`+2g[G##?T-rLjek(1&@#8sS
3bK&\U^*A:sWk2U[B̸{)/FD`pduoULZ} 3[
]WD	|kQKB:r"j=_;uVTN3^\6KrbJ mjcc>~ȩ2N{ut81u<#9"JSOc{iu`9fRυx	s}tn'y+ns*o_%/mf߲@F8f{{bc{[>5'ԤY0Ϫ<Ӱl8(_jTnon=Λ6|z6<080U0U00Um9{D&P70?U6020.*&(http://web.irtnog.org/irtnog-root-ca.crl=http://cinip100ntsbs.irtnog.net/CertEnroll/irtnog-root-ca.crlldap:///CN=irtnog-root-ca,CN=cinip100ntsbs,CN=CDP,CN=Public%20Key%20Services,CN=Services,CN=Configuration,DC=irtnog,DC=net?certificateRevocationList?base?objectClass=cRLDistributionPoint0	+70EU >0<0:	+d0-0++http://web.irtnog.org/legal/cps0[+M0I04+0(http://web.irtnog.org/irtnog-root-ca.crt0b+0Vhttp://cinip100ntsbs.irtnog.net/CertEnroll/cinip100ntsbs.irtnog.net_irtnog-root-ca.crt0+0ldap:///CN=irtnog-root-ca,CN=AIA,CN=Public%20Key%20Services,CN=Services,CN=Configuration,DC=irtnog,DC=net?cACertificate?base?objectClass=certificationAuthority0
	*H
.{L7$=(582EC|dWU
='UMѝ@	a	w6bT4.-q8g][BEإ~wO6064Ot%fk[
[vQ9X:c7*e!]5{Y!ĘzL{R(ɭ<JɅ\4WHs
?{F/gtjXeð6)>C?Q,Y.et!D.ߩfݢb91 73h(o2F'[x i鄪:~5VSQA׮LJ4ف&/o)BD7
\1r^ks/h6SN<t
A؎Fᷥ}:縀y
0㸳;Hm[]pFGDC}rK=R"ƟYӋ'v8UAW4X$9:cKm10
0T0F10
	&,dnet10
	&,dirtnog10Uirtnog-root-ca
'J0
	`He0	*H
	1	*H
0	*H
	1
120310160334Z0O	*H
	1B@^iԃ]AwzlݼΆD3ta5d9{0̷n!ڷ$$ɍOq(0c	+71V0T0F10
	&,dnet10
	&,dirtnog10Uirtnog-root-ca
'J0e*H
	1VT0F10
	&,dnet10
	&,dirtnog10Uirtnog-root-ca
'J0	*H
	100	`He*0	`He0
*H
0	`He0*H
0+0
*H
@0
*H
(0	`He0	`He0	`He0+0
*H
0
	*H
won	foQbV:N4ޙ75Ę;˸=)퉣SQ"3?s+0Hr^CԯědH&n?8Lhbz

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?BABF8C57A778F04791343E5601659908236BDC>