From owner-freebsd-questions@FreeBSD.ORG Fri Jan 16 14:00:05 2009 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 7D6901065672 for ; Fri, 16 Jan 2009 14:00:05 +0000 (UTC) (envelope-from ilikefbsd@web.de) Received: from fmmailgate02.web.de (fmmailgate02.web.de [217.72.192.227]) by mx1.freebsd.org (Postfix) with ESMTP id 2F62D8FC1C for ; Fri, 16 Jan 2009 14:00:04 +0000 (UTC) (envelope-from ilikefbsd@web.de) Received: from smtp06.web.de (fmsmtp06.dlan.cinetic.de [172.20.5.172]) by fmmailgate02.web.de (Postfix) with ESMTP id D42F5F8E98D1 for ; Fri, 16 Jan 2009 14:59:35 +0100 (CET) Received: from [85.178.47.240] (helo=[192.168.1.118]) by smtp06.web.de with asmtp (TLSv1:AES256-SHA:256) (WEB.DE 4.110 #277) id 1LNpEV-00010C-00 for freebsd-questions@freebsd.org; Fri, 16 Jan 2009 14:59:35 +0100 Message-ID: <497092C6.7030905@web.de> Date: Fri, 16 Jan 2009 14:59:34 +0100 From: Marco User-Agent: Thunderbird 2.0.0.19 (X11/20090110) MIME-Version: 1.0 To: freebsd-questions@freebsd.org Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: ilikefbsd@web.de X-Sender: ilikefbsd@web.de X-Provags-ID: V01U2FsdGVkX18fyCoM16hs2R/f/ZclUijeAn999xbRSAWxa05S IukVjj2sWwLCNFAAr+Ur/lXH1M3eGYlFTLaItUc1MCylbFCF3a 3pTHwiP/8= Subject: Runtime de/encryption X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 16 Jan 2009 14:00:06 -0000 Hello List, i'am using the geom framework for quite a time. I'am happy about gbde/geli implementations(beside the race condition in geli) however, i wonder since some time, as the data may get exposed on a running server(as the partitions decrypted) is there a way to do some kind of runtime de/encyrption, with keys? so that only special users with the right handle can encrypt or decrypt data? so talking about another filesystem layer... Anyone? Best regards, Marco