Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 1 Jun 2016 10:40:37 -0400
From:      Eric McCorkle <eric@metricspace.net>
To:        Wojciech Puchar <wojtek@puchar.net>
Cc:        Konstantin Belousov <kostikbel@gmail.com>, freebsd-hackers@freebsd.org, Allan Jude <allanjude@freebsd.org>
Subject:   Re: EFI GELI support ready for testers
Message-ID:  <AFC9FE3D-AFB3-42A5-9D54-A54F1CC87A7F@metricspace.net>
In-Reply-To: <alpine.BSF.2.20.1606011623410.3503@laptop.wojtek.intra>
References:  <519CC1FC-84DF-4710-8E62-AF26D8AED2CF@metricspace.net> <20160528083656.GT38613@kib.kiev.ua> <d6b96a6c-4e92-35a5-e78b-cc674b6d2f25@freebsd.org> <20160528172618.GB38613@kib.kiev.ua> <6A9DADE0-B214-424A-BB14-0B0848F0D08D@metricspace.net> <20160529091827.GD38613@kib.kiev.ua> <46B3F9E2-A25B-4F9D-B35F-11AC782495B1@metricspace.net> <alpine.BSF.2.20.1606011623410.3503@laptop.wojtek.intra>

next in thread | previous in thread | raw e-mail | index | archive | help

On Jun 1, 2016, at 10:29, Wojciech Puchar <wojtek@puchar.net> wrote:

>> It's undesirable because the whole point of ZFS is to have one ZFS volume for the whole system.
> This sounds more like a religious dogma than anything else.
> 
> what if i run single disk (or mirrored 2 disk) system, no ZFS but i want everything encrypted by GELI and want only ona partition?

So do it.  I don't see the problem.

> Will you write special bootloader that would be hidden unencrypted on geli volume?

No, the boot block lives either on the ESP or the boot sector.  Same as it always has.

> Will you write 10000 special bootloaders to cope with 10000 cases of configuration FreeBSD admins want to have in the world?
> 
> Or maybe - in the future admins would not be allowed to decide and there will be only one allowed storage configuration - ZFS volume occupying all disks, with bootloader designed for that one case?

These are just straw-man arguments, and nobody has suggested anything of the sort.


Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?AFC9FE3D-AFB3-42A5-9D54-A54F1CC87A7F>