Setting Up an Encrypted Replication Task

Using Encryption in Replication Tasks

TrueNAS replication allows users to create replicated snapshots of data stored in encrypted pools, datasets or zvols as a way to back up stored data to a remote system. You can use encrypted datasets in a local replication.

Read full post gdoc_arrow_right_alt

Encrypting Datasets

TrueNAS offers ZFS encryption for your sensitive data in datasets and zvols.

Users are responsible for backing up and securing encryption keys and passphrases! Losing the ability to decrypt data is similar to a catastrophic data loss.

Data-at-rest encryption is available with:

The local TrueNAS system manages keys for data-at-rest. Users are responsible for storing and securing their keys. TrueNAS includes the Key Management Interface Protocol (KMIP).

Read full post gdoc_arrow_right_alt

Encryption

TrueNAS supports dataset and zvol encryption to secure stored data at rest.

Contents

  • Encrypting Datasets: Provides information on TrueNAS storage encryption for pools, root datasets, datasets, and zvols.

    • Encryption Screen: Provides information on the settings and functions found on the TrueNAS storage encryption screens.

      Encryption Screen

      Datasets, root, non-root parent, and child, or zvols with encryption include the Encryption widget in the set of dataset widgets shown on the Datasets screen.

      The Datasets tree table includes lock icons and descriptions that indicate the encryption state of datasets.

      IconStateDescription
      DatasetLockedEncryptionIconLockedDisplays for locked encrypted root, non-root parent and child datasets.
      DatasetUnlockedEncryptionIconUnlockedDisplays for unlocked encrypted root, non-root parent and child datasets.
      DatasetLockedByAncestorEncryptionIconLocked by ancestorDisplays for locked datasets that inherit encryption properties from the parent.
      DatasetUnlockedbyAncestorEncryptIconUnlocked by ancestorDisplays for unlocked datasets that inherit encryption properties from the parent.

      Dataset Encryption

      The Encryption option on the Pool Manager screen sets encryption for the entire pool.

      Read full post gdoc_arrow_right_alt

      Datasets Screens

      The Datasets screen and widgets show information about datasets and zvols, provide access to data management functions, indicate the dataset roles, list the services using the dataset, show encryption status, and list permissions for datasets. The screen focuses on managing data storage, including user and group quotas, snapshots, and other data protection measures.

      Datasets Screen

      The Datasets screen shows No Datasets and a Create Pool button until you add a pool and the first root dataset.

      Read full post gdoc_arrow_right_alt