Log-in |

Status

Codereview Jan 2010. Original feature set complete April 2008. Revised feature set complete May 2009

Integration Target: Q1CY10

Last onnv-gate resync: onnv_132

Videos

Need really up to the second status ?

Follow darrenmoffat on Twitter and look for tweets in the #zfs tag group.

What are we doing ?

This project will provide on disk encryption/decryption support for ZFS datasets.  The project will cover the addition of encryption and decryption to the ZFS IO pipeline and the key management for ZFS datasets.

It will support different key management strategies by allowing scripting of the zfs(1) command for key load/unload/change and an API in libzfs.

Documentation

Logging Bugs:

Bugs are tracked in Bugster: development/zfs/  with zfs-crypto keyword.

See the Project Plan page for more details.

Features

  • Per dataset policy for enabling encryption, including algorithm and key length.
  • Per dataset data encryption keys wrapped by a dataset level key
  • Inherited when keyscope property is inherited
  • Dataset wrapping key from passphrase using PKCS#5 PBE
  • Dataset wrapping key in file/stdin as raw bits or in hex
  • Encrypted swap via encrypted ZVOL
  • Support for encrypted dump ZVOL
  • NO support for encrypted boot filesystem

Futures

  • PAM module for user home directory with per dataset keying. (Currently implemented but not included in ARC reviewed content).
  • Wrapping keys in PKCS#11 keystore, eg SCA-6000, TPM, Smartcard
Tags:
Created by on 2009/10/26 11:40
Last modified by darrenm on 2010/01/25 19:24

Collectives

Project


© 2010, Oracle Corporation and/or its affiliates
XWiki Enterprise 2.1.1.25889 - Documentation
Terms Of Use | Privacy | Trademarks | Copyright Policy | Site Guidelines | Site map | Help
Your use of this web site or any of its content or software indicates your agreement to be bound by these Terms of Use.
Oracle