Replication of encrypted pool

Status
Not open for further replies.

PetrZ

Dabbler
Joined
Feb 23, 2018
Messages
20
Hi.
I would like to ask, how it's about replication of encrypted pool.
Is needed to use strong (or any) cipher as decrypted data are transferred,
or is already safe as "drive data" (already encrypted) are transferred?
 

Ericloewe

Server Wrangler
Moderator
Joined
Feb 15, 2014
Messages
20,194
There are two situations here:

FreeNAS GELI disk encryption - This has zero effect on zfs send. All operations are on unencrypted data and you need to secure the transport and the other end as needed.

ZFS native dataset encryption - Using encrypted send, most user data is sent encrypted, with metadata not being encrypted (it's necessarily unencrypted to allow for stuff like scrubs on encrypted pools). You may want to still encrypt the transport. Regular unencrypted send is still a possibility here and the first point applies. Native encryption is not yet available in FreeNAS.
 
Status
Not open for further replies.
Top