Encryption at Rest in ZFS
Tom Caputi tcaputi@datto.com
Encryption at Rest in ZFS Tom Caputi tcaputi@datto.com Overview of - - PowerPoint PPT Presentation
Encryption at Rest in ZFS Tom Caputi tcaputi@datto.com Overview of Encryption Implementation 2 What is Encryption? Want to prevent someone (an attacker) from accessing private data Permissions arent good enough Root user can
Tom Caputi tcaputi@datto.com
2
3
4
5
6
Encrypted
Not Encrypted
7
8
zfs create \
pool/encrypted_ds
9
10
11
12
13
zfs create \
[-o pbkdf2iters=<value>] \ <dataset name>
14
zfs unload-key <dataset>
zfs load-key <dataset>
15
zfs change-key [-li] \ [-o keylocation=<key location>] \ [-o keyformat=<key format>] \ [-o pbkdf2iters=<value>] \ <dataset name>
16
17
zfs send -r
18
19
Tom Caputi tcaputi@datto.com https://github.com/zfsonlinux/zfs/pull/5769