1 |
On Tue, 12 Dec 2017 12:18:23 +0000, Wols Lists wrote: |
2 |
|
3 |
> > That means every write has to be encrypted 4 times, whereas using |
4 |
> > encryption in the filesystem means it only has to be done once. I |
5 |
> > tried setting encrypted BTRFS this way and there was a significant |
6 |
> > performance hit. I'm seriously considering going back to ZoL now that |
7 |
> > encryption is on the way. |
8 |
> |
9 |
> DISCLAIMER - I DON'T HAVE A CLUE HOW THIS ACTUALLY WORKS IN DETAIL |
10 |
> |
11 |
> but there's been a fair few posts on LKML sublists about how linux is |
12 |
> very inefficient at using hardware encryption. Setup/teardown is |
13 |
> expensive, and it only encrypts in small disk-size blocks, so somebody's |
14 |
> been trying to make it encrypt in file-system-sized chunks. When/if they |
15 |
> get this working, you'll probably notice a speedup of the order of 90% |
16 |
> or so ... |
17 |
|
18 |
This isn't so much a matter of hardware vs. software encryption, more |
19 |
that encrypting below the RAID level means everything has to be encrypted |
20 |
multiple times. |
21 |
|
22 |
|
23 |
-- |
24 |
Neil Bothwick |
25 |
|
26 |
There's no place like ~ |