Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 25 Jul 2000 10:29:01 +0200
From:      Terje Elde <terje@elde.net>
To:        Adrian Chadd <adrian@FreeBSD.ORG>
Cc:        Robert Watson <rwatson@FreeBSD.ORG>, Sheldon Hearn <sheldonh@uunet.co.za>, =?iso-8859-1?Q?Joachim_Str=F6mbergson?= <watchman@ludd.luth.se>, Greg Lewis <glewis@trc.adelaide.edu.au>, freebsd-security@FreeBSD.ORG
Subject:   Re: Status of FreeBSD security work? Audit, regression and crypto swap?
Message-ID:  <20000725102901.A32679@dlt.follo.net>
In-Reply-To: <20000724210042.O62551@ywing.creative.net.au>; from adrian@FreeBSD.ORG on Mon, Jul 24, 2000 at 09:00:42PM %2B0200
References:  <Pine.BSF.4.21.0007181838570.28415-100000@achilles.silby.com> <Pine.NEB.3.96L.1000719165025.73365A-100000@fledge.watson.org> <20000720124805.D70017@dlt.follo.net> <20000724210042.O62551@ywing.creative.net.au>

next in thread | previous in thread | raw e-mail | index | archive | help
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

* Adrian Chadd (adrian@FreeBSD.ORG) [000724 21:40]:
> > For a "ugly hack, but up and running today" kinda solution, you could always
> > do what I do... Use cfs (yes, the software tcfs is based on is running under
> > freebsd, and is available in the ports collection) for your file systems, then
> > swap to a file, on one of the encrypted file systems.
> > 
> > It's not a pretty sight, but it does the job.
> 
> Whats wrong with a bdev io layer like vinum/ccd which does crypto?
> Then you could swap and filesystem to your block devices to your hearts
> content with whatever filesystem you wanted?

This would work, and probably significantly faster than the cfs model, with
it's double mount points and so on. It would however also (IMHO) fall under
the not pretty hack umbrella, as this doesn't easily allow handling of multi
user situations and so on.

Bottom line in this case is that if anyone wants to spend a weekend coding
this up then that will be an advantage for all the people wanting to use
encrypted homedirs and swap on single user workstations. It will make the
world a little better, but it might also delay implementation and deployment of
a proper system.

As far as I can see what it all boils down to is that this will be coded if
someone wants it bad enough to take the time. Then we'll just have to see if
it delays other good stuff...

To finish off with some questions...

Does anyone at this time plan on taking the time to look at integrating TCFS
into FreeBSD?
Are there any other possibilities than a bdev io layer, cfs and tcfs?

Terje
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.2 (FreeBSD)
Comment: For info see http://www.gnupg.org

iD8DBQE5fU/H8HLgLrwmRg0RAqfrAJ9Rozagx6bFj65OITuE/nQhDp+zUgCfbOvK
S7I824Obbdg1lQzhHr2M6H0=
=f6sI
-----END PGP SIGNATURE-----


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20000725102901.A32679>