Locked ZFS Encrypted Dataset visible on network and can be written to creating data leak.

Paul5

Contributor
Joined
Jun 17, 2013
Messages
117
TrueNAS 12_U6 Test set-up to get feel of ZFS encryption and move away from Geli:

Clean Install:
Network configured.
Only FTP switched on with Allow Root Access.
One Hdd > Pool created
> DatasetEncryptedTest - Passphrase protected.
> DatasetNotEncryptedTest

Nothing else no shares, users, groups.

Filezilla login via FTP
:
Unlocked encrypted dataset present read write all good > locked > refreshed > data cleared but dataset still available.
Locked encrypted dataset still available > refreshed and still present can also be written to > Unlock and data is cleared permanently?

In my 11.3 a locked Geli Pool will not appear on the network and if locked it disappears as it should.

In TN-12-U6 This can't be right for it's one huge bug with massive data loss/leak of unprotected data left in created folders for their is also no notice of Dataset state on the clients. See the attached image for data leak folders created by TN12-U6

If the Dataset is locked it should not appear on the network yet alone allow write.
 

Attachments

  • data leak0.png
    data leak0.png
    159.9 KB · Views: 164
Last edited:
Top