Re: OpenZFS: using an encrypted dataset without a prompt for its passphrase

From: Ryan Moeller <freqlabs_at_FreeBSD.org>
Date: Sat, 17 Oct 2020 03:40:38 -0400
On 10/17/20 1:54 AM, Graham Perrin wrote:
> root_at_momh167-gjp4-8570p:~ # zfs get all Transcend/VirtualBox | grep -e 
> creation -e key -e crypt
> Transcend/VirtualBox  creation              Wed Sep  2 19:02 2020     -
> Transcend/VirtualBox  encryption aes-256-gcm               -
> Transcend/VirtualBox  keylocation prompt                    local
> Transcend/VirtualBox  keyformat passphrase                -
> Transcend/VirtualBox  encryptionroot Transcend/VirtualBox      -
> Transcend/VirtualBox  keystatus unavailable               -
> root_at_momh167-gjp4-8570p:~ #
>
> I was prompted in early September but since then, no prompts.
>
> I can export and import the pool (Transcend) without entering the 
> passphrase.
>
> Is this intended behaviour and if so: how does the pool – or the 
> computer to which I connect the device (a mobile hard disk drive) – 
> know that entry of the phrase is unnecessary?


This is intentional. The pool can be imported but the filesystem is not 
mounted until the key is loaded.

See zfs-load-key(8)

-Ryan


> _______________________________________________
> freebsd-current_at_freebsd.org mailing list
> https://lists.freebsd.org/mailman/listinfo/freebsd-current
> To unsubscribe, send any mail to 
> "freebsd-current-unsubscribe_at_freebsd.org"
Received on Sat Oct 17 2020 - 05:40:39 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:41:25 UTC