ZFS auto load key / TPM

XelNaha

Active Member
Apr 6, 2019
20
0
41
43
Hello,

I have a proxmox server remotely in a not-so-extremely-secure location. I can't change this due to various restricting factors, however I would like to encrypt the zfs drives. Doing this is relatively simple, however can we load the encryption key on boot and preferably from say TPM or other way checking the integrity of the system?

I tried looking in the forum / documentation but can't find anything of the sort.

thanks
 
There is no official support for anything like that. Also, if you don't trust the environment, wouldn't such an automatic unlocking be a bit nonsensical as anyone who has access to the physical machine, would be able to boot it up?