encrypt whole system using zfs

Lars Kristiansen lars+lister.freebsd at adventuras.no
Thu Jul 29 12:35:31 UTC 2010


  Den 29.07.2010 13:26, skrev Jozsi Vadkan:
> With dm_crypt&lvm, i can install a Debian [in sraid1], that has only the
> mbr&  the "/boot" unencrypted.
>
> So if someone steals the server/hdds, it can't do anything to them.
> That's ok.
>
>
> I'm a newbie to FreeBSD, and I want to use it in the future. I'm looking
> for these "features", that i mentioned above.
>
> So, if someone has a little time, can someone post just a few
> howtos/links, how to do this? [i mean what is the "best-practise" for
> this? - to encrypt the whole system/data. And e.g.: the /boot&  the mbr
> would stay unencrypted]
>
> e.g.: How to install a FreeBSD in encrypted ZFS [and ZFS does the
> mirroring instead of RAID-1]
>
> Thank you!
>
> _______________________________________________
> freebsd-questions at freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-questions
> To unsubscribe, send any mail to "freebsd-questions-unsubscribe at freebsd.org"
Hi!
The latest pcbsd does this.
If you make a /boot partition, it will keep the keys there, and you may 
populate the geli encrypted area with zfs if you like.
Even if pc-bsd is not your choice, an installation might be a nice 
tutorial in the subject.

Regards,
  Lars



More information about the freebsd-questions mailing list