Lock encrypted volume via API

Status
Not open for further replies.

SweetAndLow

Sweet'NASty
Joined
Nov 6, 2013
Messages
6,421

cyberjock

Inactive Account
Joined
Mar 25, 2012
Messages
19,526
That doesn't lock the pool.

The pool cannot be locked (except by server reboot). The reason is that the encryption is designed to protect your data from theft, RMAs, etc. In any case the disk would be removed from the server or the server would be power-cycled. In both cases the encryption prevents the disk from auto-mounting.

This feature has been requested several times, and the devs are adamantly against it because that was not in the security model and doesn't fortify the designed security. In fact, there's no guarantee there isn't some gaping security hole in the encryption FreeNAS uses because of a bug or something. It hasn't been audited by some security professionals that I know of. So the big picture is that you should expect the encryption to only stop the least sophisticated attacker.
 
Status
Not open for further replies.
Top