On Tue, 2006-08-15 at 12:47 -0700, Eric Schrock wrote:

> The copy-on-write nature of ZFS makes this extremely difficult,
> particularly w.r.t. to snapshots.  That's not to say it can't be solved,
> only that it won't be solved in the near term (i.e. within the next
> year).  The timeframe for ZFS crypto support is much shorter, and this
> requirement is entirely reasonable for an initial implementation.

So, maybe we're doing these projects in the wrong order, then -- my
experience with implementing systems using cryptography is that unless
you design, implement, *and* test algorithm and key agility from the
beginning, you will have to throw away a lot more than you originally
expected to when you try to add it in later.

                                                - Bill


_______________________________________________
zfs-discuss mailing list
zfs-discuss@opensolaris.org
http://mail.opensolaris.org/mailman/listinfo/zfs-discuss

Reply via email to