encryption

  1. A

    FIPS mode on tape library - PBS errors out on labeling

    Hi all, We've run into a problem commissioning our new tape backup solution. Since we're in a heavily regulated industry, we're required to adhere to FIPS 140-2, which means using HPE's MSL Encryption Kit for validated FIPS 140-2 encryption on our Ultrium 9-SCSi drive. This seems to be...
  2. P

    Struggling with ZFS [SOLVED]

    I've migrated all my VMs across to Proxmox over the last 12 months, all that remains is an encrypted one. I would like to rebuild it from scratch as a VM on proxmox. I understand ZFS encryption is the way to go. I'm trying to add ZFS pool using the GUI, but my disks do not appear in the list of...
  3. M

    [TUTORIAL] Encrypt complete Proxmox VE node with LUKS

    I was interested in encrypting my Proxmox VE nodes and found that there are many threads spread across this forum. It took me a lot of work to find everything I needed, so I thought it would be a good idea to collect everything in one how-to guide. I’ve published it on GitHub for easy...
  4. C

    Backup encryption

    I have seen that in Proxmox Backup is an option to encrypt the backups. In proxmox itself i couldn't find a way to protect the containers and vms. LXCs are directorys if somone gets the backup it's easy to get all data stored in the backup archive. Is there a hidden option in Proxmox...
  5. H

    [SOLVED] re-encrypt backups

    Good day, I have a case where the encryption keys had been compromised (failed partnership), and there are a specific set of backups I'd like to re-encrypt with a new encryption key. ie. decrypt the current backup sets, en re-write then with a new backup encryption key. Q1: That is not an...
  6. B

    File server recommendation

    Hello! I've never had a file server, but I now I think I need to have one as a PVE guest, a very basic one. I'd like something simple and easy, with a GUI. Its only purpose will be to store some simple data of a few vms and containers. I would go for the Turnkey file server LXC container but I...
  7. A

    Encrypted ZFS datasets empty after manual mount

    Hello! I am struggling with a quite weird problem imho. Running Proxmox 7.4.1 (without subscription) without any issues for a long time until recently the SATA controller card locked up and I had to do a hard shutdown. Connected the 4 harddrives to the internal ports and booted up. The pool...
  8. P

    PVE limitations with encrypted ZFS datasets

    Hi all, I recently stumbled when trying to migrate a VM from a node with an encrypted ZFS dataset to a node without encryption: ``` cannot send nvmepool/vm-310-disk-0@__migration__: encrypted dataset nvmepool/vm-310-disk-0 may not be sent with properties without the raw flag ``` It's not a...
  9. T

    Encryption in Transit

    Hello, I have a couple questions about a Proxmox Virtual Environment (PVE) connected to a Proxmox Backup Server (PBS). If the following setting is set to "Do not encrypt backups"... Then... 1) Is the data that is sent from PVE to PBS still encrypted in Transit? If yes to 1... 2) Has...
  10. E

    Mounting encrypted ZFS dataset on boot

    I have an encrypted dataset which contains resources Proxmox needs (e.g. vm storage). The passphrase is in /etc/zfs/datasetname.phrase and that path is stored in zfs keylocation It gets properly mounted when I zfs mount -a -l without me needing to enter the passphrase. This is not the boot...
  11. S

    Backups are not being encrypted via backup-client-script

    Hello, we have a script that we setup to use the backup-client on a external servers which simply calls the backup-client exports the encryption key and password and then selects the diretories we want to backup. This script works fine on all of our servers except one server. The backups do...
  12. K

    [SOLVED] Recommend way for encryption

    I am going to install PVE at my office. For the security policy of my office, I have to encrypt all disks. I have experience of PVE installation at my homelab without encryption, FYI. At first, I thought I can utilize zfs encryption but I am hesitating after I have read this...
  13. A

    Replication of encrypted zvols

    Hi all, I'm running proxmox 8.2.2 on encrypted ZFS, basically as described at https://privsec.dev/posts/linux/using-native-zfs-encryption-with-proxmox/. I know this isn't supported, but it works fine, except for zvol replication. Replication wants to preserve properties, and sending an...
  14. R

    Issues using pvse

    Hello I am having some issues. I have several nodes in a cluster that I want local encrypted zfs pools for storage but I can't add the pools using the same name on different proxmox nodes, so I can't easily migrate between encryped zfs pools. Steps to reproduce: #1. Create the base disk in the...
  15. A

    Encrpytion light on tape drive lit?

    I just noticed when running a backup, the hardware Encryption light was lit on my drive for one of my tapes. This tape has been used without hardware encryption in the past. Has PBS made a change to the way encryption is implemented, now using the hardware encryption by default? Has PBS just...
  16. S

    Encrypting a single LXC container on LVM?

    Hey there, i'm currently trying to figure out if it's possible to encrypt a single (privileged, if that matters at all) LXC container on an unencrypted LVM-VG (currently lvm-thin)? I've got the data for that container encrypted via ZFS encryption, but unfortunately i only have ZFS on HDD and...
  17. W

    de-duplication with encryption inside vm

    Hello, I was hoping to get some clarity about backups and encryption from inside a vm. If I encrypt a debian vm with luks on lvm, will this interfere with proxmox backup server de-duplication, pruning, etc? To clarify, the encryption in not happening in proxmox, but within the vm. Any other...
  18. M

    [SOLVED] Slow ZFS encryption: will we get a fix for AVX/AVX2 not being selected?

    There is an ongoing discussion about slow encrypted ZFS performance, e.g. here: https://github.com/openzfs/zfs/issues/15245 and here: https://github.com/openzfs/zfs/issues/15276 Obviously this is due to a regression introduced in kernel 5.15.0-82 and discussed here...
  19. R

    Ceph RBD image encryption

    Hi There!, Has anyone used or had the experience of activating Ceph's RBD image encryption? RBD Image encryption What I want is to have encrypted disks of some VMs. OSD encryption doesn't solve this case, as it doesn't protect against an attacker gaining access to the host. I also had a look...
  20. N

    Need help installing Proxmox with automatic decryption and multiple drives

    I'm trying to install Proxmox on a server that is going to be running Home Assistant, a security camera NVR setup and other sensitive data, I need to have the drives be encrypted with automatic decryption of drives so the VMs can automatically resume after a power failure. # My desired setup...