Date: Sat, 10 Mar 2012 11:03:34 -0500 From: "Matthew X. Economou" <xenophon@irtnog.org> To: <freebsd-stable@freebsd.org> Subject: RE: FreeBSD root on a geli-encrypted ZFS pool Message-ID: <BABF8C57A778F04791343E5601659908236BDC@cinip100ntsbs.irtnog.net> In-Reply-To: <20120309152253.17a108c2@fabiankeil.de> References: <BABF8C57A778F04791343E5601659908236BD9@cinip100ntsbs.irtnog.net><20120307174850.746a6b0a@fabiankeil.de><BABF8C57A778F04791343E5601659908236BDA@cinip100ntsbs.irtnog.net> <20120309152253.17a108c2@fabiankeil.de>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --]
Fabian Keil writes:
> In my opinion protecting ZFS's default checksums (which cover
> non-metadata as well) with GEOM_ELI is sufficient. I don't see
> what advantage additionally enabling GEOM_ELI's integrity
> verification offers.
I follow you now. You may be right about the extra integrity checking
being redundant with ZFS.
> Anyway, it's a test without file system so the ZFS overhead isn't
> measured. I wasn't entirely clear about it, but my assumption was
> that the ZFS overhead might be big enough to make the difference
> between HMAC/MD5 and HMAC/SHA256 a lot less significant.
Got it. That also makes sense. I'll put this on my to-test list.
> I'm currently using sector sizes between 512 and 8192 so I'm not
> actually expecting technical problems, it's just not clear to me
> how much the sector size matters and if 4096 is actually the best
> value when using ZFS.
The geli(8) manual page claims that larger sector sizes lower the
overhead of GEOM_ELI keying initialization and encryption/decryption
steps by requiring fewer of these compute-intensive setup operations
per block. You can think of it in terms of networking, where it makes
sense to re-use a TCP connection for multiple HTTP requests, because
for small HTTP requests, the bandwidth and latency caused by the TCP
three-way handshake overshadows the actual data transfer.
--
I FIGHT FOR THE USERS
[-- Attachment #2 --]
0 *H
010
`He 0 *H
00
'J 0
*H
0F10
&,dnet10
&,dirtnog10Uirtnog-root-ca0
120121220200Z
120918223956Z010
&,dnet10
&,dirtnog10U
MyBusiness10UUsers10USBSUsers10UMatthew X. Economou1"0 *H
xenophon@irtnog.org00
*H
0 ywxxv-4物.4aO@25NiC{
& jѩm'w♛
%jm} dxG"WdR Ԕ
&%'N
?
Z4 00 +7
U s e r0)U%"0
+7
++0U0D *H
7050*H
0*H
0+0
*H
0CU<0:#
+7xenophon@irtnog.netxenophon@irtnog.org0U)}.o]g^-0U#0m9{D&P70?U6020.*&ldap:///CN=irtnog-root-ca,CN=cinip100ntsbs,CN=CDP,CN=Public%20Key%20Services,CN=Services,CN=Configuration,DC=irtnog,DC=net?certificateRevocationList?base?objectClass=cRLDistributionPoint=http://cinip100ntsbs.irtnog.net/CertEnroll/irtnog-root-ca.crl(http://web.irtnog.org/irtnog-root-ca.crl0[+M0I0+0ldap:///CN=irtnog-root-ca,CN=AIA,CN=Public%20Key%20Services,CN=Services,CN=Configuration,DC=irtnog,DC=net?cACertificate?base?objectClass=certificationAuthority0b+0Vhttp://cinip100ntsbs.irtnog.net/CertEnroll/cinip100ntsbs.irtnog.net_irtnog-root-ca.crt04+0(http://web.irtnog.org/irtnog-root-ca.crt0
*H
Ghưn< E5Re9!{*VFm0f?_;Rg*:Y؞'֑T\Jh #Œu.F XdnS.[!x^Y1ey`MS1h-13F*-);ȖAsD8K2ZǮ)w*SM~c gAX9ᕉx2Dkb큋`:hWRE0
eX`Tb*a |]G2[5J+ਁC1
FkB6_ʝ(J/wYl}C7aoY헀G tJnP/qgR|Ŧk]TIyu.P)[ZWZJu@5t\:\k`U!Iy/H|vQ\s,;mepm3
7p^l|e͠2tM@4Gm0T0< Du@CQ(ĤE0
*H
0F10
&,dnet10
&,dirtnog10Uirtnog-root-ca0
070918223246Z
120918223956Z0F10
&,dnet10
&,dirtnog10Uirtnog-root-ca0"0
*H
0
:~.*S ӯr햝 ًjoףZ >>@ "L&!,,UAo8-Eh`+2g[G##?T-rLjek(1&@#8sS
3bK&\U^*A:sWk2U[B̸{)/FD`pduoULZ} 3[
]WD |kQKB:r"j=_;uVTN3^\6KrbJ mjcc>~ȩ2N{ut81u<#9"JSOc{iu`9fRυx s}tn'y+ns*o_%/mf߲@F8f{{bc{[>5'ԤY0Ϫ<Ӱl8(_jTnon=Λ6|z6 <080U0U00Um9{D&P70?U6020.*&(http://web.irtnog.org/irtnog-root-ca.crl=http://cinip100ntsbs.irtnog.net/CertEnroll/irtnog-root-ca.crlldap:///CN=irtnog-root-ca,CN=cinip100ntsbs,CN=CDP,CN=Public%20Key%20Services,CN=Services,CN=Configuration,DC=irtnog,DC=net?certificateRevocationList?base?objectClass=cRLDistributionPoint0 +7 0EU >0<0: +d 0-0++http://web.irtnog.org/legal/cps0[+M0I04+0(http://web.irtnog.org/irtnog-root-ca.crt0b+0Vhttp://cinip100ntsbs.irtnog.net/CertEnroll/cinip100ntsbs.irtnog.net_irtnog-root-ca.crt0+0ldap:///CN=irtnog-root-ca,CN=AIA,CN=Public%20Key%20Services,CN=Services,CN=Configuration,DC=irtnog,DC=net?cACertificate?base?objectClass=certificationAuthority0
*H
.{L7$=(582EC|dWU
='UMѝ@ a w6bT4.-q8g][BEإ~wO6064Ot%fk[
[vQ9X:c7*e!]5{Y!ĘzL{R(ɭ<JɅ\4WHs
?{ F/gtjXeð6)>C?Q,Y.et!D.ߩfݢb91 73h(o2F'[ x i鄪:~5VSQALJ4ف&/o)BD7
\1r^ks/h6SN<t
A؎Fᷥ}:縀y
0㸳;Hm[]pFGDC}rK=R"ƟYӋ'v8UAW4 X$9:cKm10
0T0F10
&,dnet10
&,dirtnog10Uirtnog-root-ca
'J 0
`He 0 *H
1 *H
0 *H
1
120310160334Z0O *H
1B@^iԃ]AwzlݼΆD3ta5d9{0̷n!ڷ$$ɍOq(0c +71V0T0F10
&,dnet10
&,dirtnog10Uirtnog-root-ca
'J 0e*H
1VT0F10
&,dnet10
&,dirtnog10Uirtnog-root-ca
'J 0 *H
100 `He*0 `He0
*H
0 `He0*H
0+0
*H
@0
*H
(0 `He0 `He0 `He0+0
*H
0
*H
won foQbV:N4ޙ75Ę;˸=)퉣SQ"3?s+0Hr^CԯědH&n?8Lhbz
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?BABF8C57A778F04791343E5601659908236BDC>
