EFI GELI support ready for testers

Eric McCorkle eric at metricspace.net
Wed Jun 1 14:40:38 UTC 2016


On Jun 1, 2016, at 10:29, Wojciech Puchar <wojtek at puchar.net> wrote:

>> It's undesirable because the whole point of ZFS is to have one ZFS volume for the whole system.
> This sounds more like a religious dogma than anything else.
> 
> what if i run single disk (or mirrored 2 disk) system, no ZFS but i want everything encrypted by GELI and want only ona partition?

So do it.  I don't see the problem.

> Will you write special bootloader that would be hidden unencrypted on geli volume?

No, the boot block lives either on the ESP or the boot sector.  Same as it always has.

> Will you write 10000 special bootloaders to cope with 10000 cases of configuration FreeBSD admins want to have in the world?
> 
> Or maybe - in the future admins would not be allowed to decide and there will be only one allowed storage configuration - ZFS volume occupying all disks, with bootloader designed for that one case?

These are just straw-man arguments, and nobody has suggested anything of the sort.


More information about the freebsd-hackers mailing list