DM-Crypt Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: David Christensen <dpchrist@holgerdanske.com>
To: dm-crypt@saout.de
Subject: Re: [dm-crypt] security concerns with RAID on top of dmcrpyt and with mulitple devices with the same key slot key?
Date: Thu, 2 Jun 2016 21:36:47 -0700	[thread overview]
Message-ID: <5751095F.8020306@holgerdanske.com> (raw)
In-Reply-To: <1464923675.2806.13.camel@scientia.net>

On 06/02/2016 08:14 PM, Christoph Anton Mitterer wrote:
> On Thu, 2016-06-02 at 19:41 -0700, David Christensen wrote:
>> If you put encryption on top of a RAID of N devices, your CPU will
>> have
>> to process one layer of encryption.  If you put a RAID on top of N
>> encrypted devices, your CPU will have to process N layers of
>> encryption.
> Well that's of course clear (I should have mentioned this),... but I
> cannot do the former with btrfs RAID, which in turn has the nice
> feature of being able to (try to) recover from silent block corruption
> (via the checksums), which MD RAID cannot.

Similarly, OpenZFS on encrypted volumes.


>> For stability, the kernel, device drivers, dm-crypt, LVM, btrfs,
>> etc.,
>> need to function correctly under concurrent workloads.  Choose your
>> software accordingly.
> Well...are there any current known issues in here? I used to remember
> that btrfs once had problems on top of dm-crypt, but that's long ago.

My laptop has Debian 7 (Wheezy) with btrfs root on LUKS on one SSD 
partition.  Both my kernel and btrfs versions are fairly old.  So, my 
btrfs is lacking features.  When I install btrfs-tools, it issues 
warnings about btrfs being under heavy development.  But, the laptop 
seems to work reliably.


You might want to dig through the bug reports for the various pieces on 
whatever Linux distribution and release you are considering.


David

      reply	other threads:[~2016-06-03  4:36 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-06-02 23:47 [dm-crypt] security concerns with RAID on top of dmcrpyt and with mulitple devices with the same key slot key? Christoph Anton Mitterer
2016-06-03  2:41 ` David Christensen
2016-06-03  3:14   ` Christoph Anton Mitterer
2016-06-03  4:36     ` David Christensen [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=5751095F.8020306@holgerdanske.com \
    --to=dpchrist@holgerdanske.com \
    --cc=dm-crypt@saout.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox