Hi there,
I wondered what the best solution is to encrypt parts of a ZFS pool. As far as i know the recommended method for encryption is to encrypt the whole disks and create a ZFS pool from these encrypted volumes.
Is there a way to encrypt only specific ZFS datasets of a non encrypted ZFS pool?
The benefit of this would be more performance for data which is not in need to be encrypted (which is the majority of the data in this case).
Somewhere I read about creating a ZFS pool, then creating ZFS volumes and encrypt these, and create a new ZFS pool from those volumes (ZFS->ELI->ZFS). How much of a performance loss would you have to take with this approach?
And related to that:
Does encryption in either of these two ways (ELI->ZFS pool) or (ZFS->ELI->ZFS) in any way "harm" or loosen ZFS's benefits related to data integrity?
I think the ZFS->ELI->ZFS method is more "secure" against data corruption because of the underlying ZFS layer, is this assumption correct?
Thanks
S.
This is the old XigmaNAS forum in read only mode,
it will taken offline by the end of march 2021!
I like to aks Users and Admins to rewrite/take over important post from here into the new fresh main forum!
Its not possible for us to export from here and import it to the main forum!
it will taken offline by the end of march 2021!
I like to aks Users and Admins to rewrite/take over important post from here into the new fresh main forum!
Its not possible for us to export from here and import it to the main forum!
Partial encrypt a ZFS pool
- raulfg3
- Site Admin

- Posts: 4865
- Joined: 22 Jun 2012 22:13
- Location: Madrid (ESPAÑA)
- Contact:
- Status: Offline
Re: Partial encrypt a ZFS pool
Sorry, no experience here, only read this in the ReadMe:
51 Permanent restrictions:
52 - It is not possible to format a SoftRAID disk with MSDOS FAT16/32.
53 - It is not possible to encrypt a disk partition, only complete disks are supported.
54 - Enable 'polling' on interfaces used by a LAGG interface will make it inoperable.
51 Permanent restrictions:
52 - It is not possible to format a SoftRAID disk with MSDOS FAT16/32.
53 - It is not possible to encrypt a disk partition, only complete disks are supported.
54 - Enable 'polling' on interfaces used by a LAGG interface will make it inoperable.
12.1.0.4 - Ingva (revision 7743) on SUPERMICRO X8SIL-F 8GB of ECC RAM, 11x3TB disk in 1 vdev = Vpool = 32TB Raw size , so 29TB usable size (I Have other NAS as Backup)
Wiki
Last changes
HP T510
Wiki
Last changes
HP T510
