Re: OpenZFS: using an encrypted dataset without a prompt for its passphrase

From: Graham Perrin <grahamperrin_at_gmail.com>
Date: Sat, 17 Oct 2020 14:02:47 +0100
On 17/10/2020 12:35, Ryan Moeller wrote:
>
> On 10/17/20 5:55 AM, Graham Perrin wrote:
>> On 17/10/2020 08:40, Ryan Moeller wrote:
>>> This is intentional. The pool can be imported but the filesystem is 
>>> not mounted until the key is loaded. 
>>
>> Thanks, the file system mounts without me entering a passphrase; is 
>> this intentional?
>>
>
> It shouldn't be possible.
>
> # zfs mount storage/crypt
> cannot mount 'storage/crypt': encryption key not loaded

root_at_momh167-gjp4-8570p:~ # date ; uname -v ; uptime
Sat Oct 17 14:00:10 BST 2020
FreeBSD 13.0-CURRENT #69 r366648: Tue Oct 13 05:49:05 BST 2020 
root_at_momh167-gjp4-8570p:/usr/obj/usr/src/amd64.amd64/sys/GENERIC-NODEBUG
  2:00PM  up 9 mins, 5 users, load averages: 0.29, 0.56, 0.31
root_at_momh167-gjp4-8570p:~ # zpool export Transcend && ls -hl 
/Volumes/t500/VirtualBox ; zpool import Transcend && ls -hl 
/Volumes/t500/VirtualBox
ls: /Volumes/t500/VirtualBox: No such file or directory
total 18
drwxr-xr-x  2 grahamperrin  grahamperrin     2B Sep 11 19:28 CloudReady
drwxr-xr-x  6 grahamperrin  grahamperrin     6B May  8 09:04 FreeBSD
drwxr-xr-x  4 grahamperrin  grahamperrin     4B Sep 20 17:03 Linux
drwxr-xr-x  4 grahamperrin  grahamperrin     7B Oct 16 17:41 Windows
root_at_momh167-gjp4-8570p:~ # zfs get all Transcend/VirtualBox | grep -e 
crypt -e key -e mountpoint | sort
Transcend/VirtualBox  encryption aes-256-gcm               -
Transcend/VirtualBox  encryptionroot Transcend/VirtualBox      -
Transcend/VirtualBox  keyformat passphrase                -
Transcend/VirtualBox  keylocation prompt                    local
Transcend/VirtualBox  keystatus unavailable               -
Transcend/VirtualBox  mountpoint /Volumes/t500/VirtualBox  inherited 
from Transcend
root_at_momh167-gjp4-8570p:~ # zfs --version
zfs-0.8.0-1
zfs-kmod-v2020100400-zfs_79f0935fa
root_at_momh167-gjp4-8570p:~ #
Received on Sat Oct 17 2020 - 11:02:52 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:41:25 UTC