From owner-freebsd-current@freebsd.org Sat Apr 18 04:01:04 2020 Return-Path: Delivered-To: freebsd-current@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id BF5622B88ED; Sat, 18 Apr 2020 04:01:04 +0000 (UTC) (envelope-from pete@nomadlogic.org) Received: from mail.nomadlogic.org (mail.nomadlogic.org [174.136.98.114]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) server-signature RSA-PSS (4096 bits) client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "mail.nomadlogic.org", Issuer "Let's Encrypt Authority X3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 493zlh2td0z4NR3; Sat, 18 Apr 2020 04:01:04 +0000 (UTC) (envelope-from pete@nomadlogic.org) Received: from [192.168.1.216] (cpe-23-243-162-239.socal.res.rr.com [23.243.162.239]) by mail.nomadlogic.org (OpenSMTPD) with ESMTPSA id f8384a92 (TLSv1.3:TLS_AES_256_GCM_SHA384:256:NO); Sat, 18 Apr 2020 04:01:03 +0000 (UTC) Subject: Re: OpenZFS port updated To: Ryan Moeller Cc: freebsd-current@freebsd.org, freebsd-stable@freebsd.org References: <6b25375d-0945-f01e-264e-ee410195fa97@nomadlogic.org> <0ED41E6B-9C57-405B-84BE-1161F012A974@FreeBSD.org> From: Pete Wright Message-ID: <679853e2-6113-1daa-3353-d9c5a1123a0f@nomadlogic.org> Date: Fri, 17 Apr 2020 21:01:03 -0700 User-Agent: Mozilla/5.0 (X11; FreeBSD amd64; rv:68.0) Gecko/20100101 Thunderbird/68.7.0 MIME-Version: 1.0 In-Reply-To: <0ED41E6B-9C57-405B-84BE-1161F012A974@FreeBSD.org> Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 8bit Content-Language: en-US X-Rspamd-Queue-Id: 493zlh2td0z4NR3 X-Spamd-Bar: ----- Authentication-Results: mx1.freebsd.org; none X-Spamd-Result: default: False [-6.00 / 15.00]; NEURAL_HAM_MEDIUM(-1.00)[-0.999,0]; REPLY(-4.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000,0] X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 18 Apr 2020 04:01:04 -0000 On 4/17/20 2:54 PM, Ryan Moeller wrote: >> On Apr 17, 2020, at 4:56 PM, Pete Wright wrote: >> >> On 4/17/20 11:35 AM, Ryan Moeller wrote: >>> FreeBSD support has been merged into the master branch of the openzfs/zfs repository, and the FreeBSD ports have been switched to this branch. >> Congratulations on this effort - big milestone! >>> OpenZFS brings many exciting features to FreeBSD, including: >>> * native encryption >> Is there a good doc reference on available for using this? I believe this is zfs filesystem level encryption and not a replacement for our existing full-disk-encryption scheme that currently works? > I’m not aware of a good current doc for this. If anyone finds/writes something, please post it! > There are some old resources you can find with a quick search that do a pretty good job of covering the basic ideas, but I think the exact syntax of commands may be slightly changed in the final implementation. > > The encryption is performed at a filesystem level (per-dataset). thanks for the clarification Ryan.  I may try to test this out in the near future and will try to record my findings in a wiki or somewhere.  being able to do filesystem level encryption is something i have several immediate use cases for. thanks! -p -- Pete Wright pete@nomadlogic.org @nomadlogicLA