1 |
On Thu, Dec 07, 2017 at 09:49:29PM +0000, Wols Lists wrote: |
2 |
|
3 |
> > So in case I ever need to send in a drive for repair/replacement, noone can |
4 |
> > read from it (or only in tiny bits'n'pieces from a hexdump), because each |
5 |
> > disk contains a mix of data and parity blocks. |
6 |
> > |
7 |
> > I think I'm finally sold. :) |
8 |
> > And with that, good night. |
9 |
> |
10 |
> So you've never heard of LUKS? |
11 |
|
12 |
Sure thing, my laptop’s whole SSD is LUKSed and so are all my other home and |
13 |
backup partitions. But encrypting ZFS is different, because every disk needs |
14 |
to be encrypted separately since there is no separation between the FS and |
15 |
the underlying block device. |
16 |
|
17 |
This will result in a big computational overhead, choking my poor Celeron. |
18 |
When I benchmarked reading from a single LUKS container in a ramdisk, it |
19 |
managed around 160 MB/s IIRC. I might give it a try over the weekend before |
20 |
I migrate my data, but I’m not expecting miracles. Should have bought an i3 |
21 |
for that. |
22 |
|
23 |
> (Oh - and md raid-5/6 also mix data and parity, so the same holds true |
24 |
> there.) |
25 |
|
26 |
Ok, wasn’t aware of that. I thought I read in a ZFS article that this were a |
27 |
special thing. |
28 |
|
29 |
-- |
30 |
Gruß | Greetings | Qapla’ |
31 |
Please do not share anything from, with or about me on any social network. |
32 |
|
33 |
This is no signature. |