Managing Self-Encrypting Drives (SED)
TrueNAS Enterprise
UI management of Self-Encrypting Drives (SED) is an Enterprise-licensed feature in TrueNAS 25.04 (and later). SED configuration options are not visible in the TrueNAS Community Edition. Community users wishing to implement SEDs can continue to do so using the command line sedutil-cli utility.
Note: Additional changes to SED management options in the TrueNAS UI ahead of the 25.04.0 release version, with documentation updates to follow.
- Legacy interface for older ATA devices (Not recommended for security-critical environments!)
- TCG Opal 1 legacy specification
- TCG Opal 2 standard for newer consumer-grade devices
- TCG Opalite which is a reduced form of OPAL 2
- TCG Pyrite Version 1 and Version 2 are similar to Opalite, but with hardware encryption removed
Pyrite provides a logical equivalent of the legacy ATA security for non-ATA devices. Only the drive firmware protects the device.Pyrite Version 1 SEDs do not have PSID support and can become unusable if the password is lost.
- TCG Enterprise designed for systems with many data disks. These SEDs cannot unlock before the operating system boots.
- TCG Ruby 1.0
See this Trusted Computing Group and NVM Express® joint white paper for more details about these specifications.