3 ms·
LUKS and the associated systemd hook shouldn't care about the filesystem, right? It's just block layer But presumably you meant native ZFS encryption, which un
by didntcheck 3y ago
LUKS and the associated systemd hook shouldn't care about the filesystem, right? It's just block layer
But presumably you meant native ZFS encryption, which unfortunately is considered to be somewhat experimental and neglected, as I understand. Which surprised me, since I thought data at rest encryption would be pretty important for an "enterprise" filesystem
Still, apparently lots of people successfully run ZFS on LUKS. It does mean you don't get zero-trust zfs send backups, but apparently that's where a lot of the bugs have been anyway
- vladvasiliu 3y agoYes, I was talking about ZFS native encryption. > But presumably you meant native ZFS encryption, which unfortunately is considered to be somewhat experimental and neglected, as I understand. Which surprised me, since I thought data at rest encryption would be pretty important for an "enterprise" filesystem. Yeah, I've happened about someone saying something similar, but I've never seen anything about that from "official" sources. Wouldn't mind a link or something if you have one on hand. But there is the fact that this encryption scheme seems limited when compared to LUKS: there's no support for multiple passphrases or using anything more convenient, like say, a U2F token. > Still, apparently lots of people successfully run ZFS on LUKS. It does mean you don't get zero-trust zfs send backups, but apparently that's where a lot of the bugs have been anyway I'd say I'm one of those people, never had any issue with this in ~ten years of use. And, indeed, the main reason for using this on my laptop is being able to send the snapshots around without having to deal with another tool for managing encryption. Also, on my servers on which I run RAIDZ, having to configure LUKS on top of each drive is a PITA.