Hello.
I'm currently working on my homeserver, which needs to be fully encrypted. I thought of encrypting my internal SSD with GELI and using a few GELI + ZFS drives for storage. But none of the setup guides covered the aspect of /boot on a separate USB dongle, only plugged in during the boot process.
There are only a few questions remaining until I feel prepared enough to start the setup:
Thanks.
I'm currently working on my homeserver, which needs to be fully encrypted. I thought of encrypting my internal SSD with GELI and using a few GELI + ZFS drives for storage. But none of the setup guides covered the aspect of /boot on a separate USB dongle, only plugged in during the boot process.
There are only a few questions remaining until I feel prepared enough to start the setup:
- How do I boot with the bootloader installed in the MBR of the SSD from my USB dongle with the /boot partition?
- The handbook states, that key files are used to encrypt, in addition to a passphrase, the master key. Is it possible to encrypt the key file with GnuPGP as I would with GNU/Linux?
- Is there a more rational way to realize a fully encrypted FreeBSD system?
Thanks.