From owner-freebsd-fs@FreeBSD.ORG Thu May 10 20:15:33 2007 Return-Path: X-Original-To: freebsd-fs@FreeBSD.org Delivered-To: freebsd-fs@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id B889816A406 for ; Thu, 10 May 2007 20:15:33 +0000 (UTC) (envelope-from gergely.czuczy@harmless.hu) Received: from marvin.harmless.hu (marvin.harmless.hu [195.56.55.204]) by mx1.freebsd.org (Postfix) with ESMTP id 3FE0313C46E for ; Thu, 10 May 2007 20:15:33 +0000 (UTC) (envelope-from gergely.czuczy@harmless.hu) Received: from localhost (marvin-mail [192.168.0.2]) by marvin.harmless.hu (Postfix) with ESMTP id C1ADD7C0C1B; Thu, 10 May 2007 22:15:30 +0200 (CEST) X-Virus-Scanned: by amavisd-new-2.4.2 (20060627) (Debian) at harmless.hu Received: from marvin.harmless.hu ([192.168.0.2]) by localhost (marvin.harmless.hu [192.168.0.2]) (amavisd-new, port 10024) with ESMTP id ueWfjPtIZOYW; Thu, 10 May 2007 22:15:30 +0200 (CEST) Received: from marvin.harmless.hu (localhost [127.0.0.1]) by marvin.harmless.hu (Postfix) with ESMTP id 543C47C0BF1; Thu, 10 May 2007 22:15:29 +0200 (CEST) Date: Thu, 10 May 2007 22:15:29 +0200 From: Gergely CZUCZY To: Dag-Erling =?utf-8?B?U23DuHJncmF2?= Message-ID: <20070510201529.GA79208@harmless.hu> References: <46432346.1060202@nipsi.de> <866470309t.fsf@dwp.des.no> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=x-unknown; protocol="application/pgp-signature"; boundary="fUYQa+Pmc3FrFX/N" Content-Disposition: inline In-Reply-To: <866470309t.fsf@dwp.des.no> User-Agent: mutt-ng/devel-r804 (FreeBSD) Cc: freebsd-fs@FreeBSD.org Subject: Re: encrypt ZFS with geli X-BeenThere: freebsd-fs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Filesystems List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 10 May 2007 20:15:33 -0000 --fUYQa+Pmc3FrFX/N Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Thu, May 10, 2007 at 10:13:18PM +0200, Dag-Erling Sm=C3=B8rgrav wrote: > Dennis Berger writes: > > I would like to know whats the best way to encrypt zfs filesystem. > > Currently I created a zfs volume with zfs create -V4g data/test. Encrypt > > it with geli init /dev/zvol/data/test. > > And create a new zpool with zpool create encrypted /dev/zvol/data/test.= eli. > > What do you suggest to do? >=20 > so you're running zfs on geli on zfs... >=20 > why not just run geli directly on the raw device and zfs on top of that? Can geli handle the resize of the partition that it encrypts? If not, then i really don't see the point in encrypting a wossname provided by zfs with geli. Bye, Gergely Czuczy mailto: gergely.czuczy@harmless.hu --=20 Weenies test. Geniuses solve problems that arise. --fUYQa+Pmc3FrFX/N Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (FreeBSD) owFtU0FrE0EUri0iLHjooaAg+i5StNnNJm1tEpukNo2lh6JgMQdPk92XzdjNzDoz m3UDHnpSRER6LaggHgUPxVPBPyD9C/4Cr559u5voxdPOm/e9773v2zfvLi/MzS+e fz19svLm+OTCl4Xz/u1RbIwI7BFTYy7siutW7I161a3Za3atVmdu3Vu9U99Yr7pr 9zsvWEcKg8LYB2mEDTD43JSjkHFxF7whUxpNMzYDu2bNcDtcR1Jzw6VoABchF/g3 d6CY0ANUdld40uciaMCzWBr07UhxYVg/RMt6IOBgGJdgn6VQcUtQdd0NYIbOjcpq o1J7uA8rLl2WYIcFdldRhwAejZqd1eZ2TQWKjSFRRNqwWrCDQnAN26gCVLDp97cE jzR3fGwRiBvUGaoFe5DIOPQh5IcIRsKhkAkkQ2Y0mCFCH7WBhOahFApPpZGByUDD gIeoU21w5OQ0nVgp0hmmROgpZKQMWI4cyzAeISTcDPO4yIL9eC0AnxlWplGMA92C PCfjpoAHGHIyksKyj+PyhKjK/0py6D3hzxgZCExgEkkZTrvlx2l2OjyN9T+upkWt CsYeaQdfQipj0HEQZAaQeF+2rVaz6hJG58llhaBiMpn+QaZLimJe+lLoOM4MngxT ENLA05iYqKKA+Vyhl/lF+MxoxRKgwbhHQkjTlNHICOSAAMy0rQ6b1g4JEWJRhppP sMAgREyZfP/yiszHqWzdhr1BNkUpwwmLUyELqbsvxbIBjQVbJGkXyfFZWaaN0YJo LRj9w0jJMffJwn6aD5i5bAW5c9Z2iiXL2s3WjWg7k9ibpNaI8dDIBk2dXztefr1F r2dE66OdYWxZtp3Z1EMUHGnn8mXYpSDWFGoZjvO+9D5GulDFFNfoWK/aCxfnsmc6 e+KL896luY8frp2+Pjs5Ovv5rdfobt58u/5pN5x7f6u+xHo3rr+88vnq7x+/2sdL 34+O/gA= =Fa2v -----END PGP SIGNATURE----- --fUYQa+Pmc3FrFX/N--