I'm sure you are going to say "YES" but please not so fast.
1. When installing FreeBSD 14.0, I am offered the choice between ZFS and UFS. If I select ZFS, the option to encrypt is there, very clear, impossible to miss. If I select UFS though, encryption is never mentioned at all. Does FreeBSD intend to "deprecate" (and eventually abandon) UFS?
2. I searched and found these among others:
And of course the official GELI documentation. I had to step away from the official GELI documentation because it's too difficullt for me to follow.
Both methods mentioned above involve using an unencrypted partition for /boot and an encrypted partition for everything else. However,
1. That's not what I want. If /boot is unencrypted, that is an obvious attack vector. The kernel could be easily tampered with. I want full encryption, EVERYTHING including boot.
2. I have installed FreeBSD with ZFS in the past and it did have full disk encryption, including boot.
So, can it be done with UFS? How?
TIA
1. When installing FreeBSD 14.0, I am offered the choice between ZFS and UFS. If I select ZFS, the option to encrypt is there, very clear, impossible to miss. If I select UFS though, encryption is never mentioned at all. Does FreeBSD intend to "deprecate" (and eventually abandon) UFS?
2. I searched and found these among others:
HOWTO: Quick GELI encryption guide
There are many ways to do this, as presented on forum, but this is the simplest method I've used. This assumes you are using UFS for your disks. I will encrypt my AsusEEE which I carry with me everywhere and holds sensitive data. This guide will encrypt whole disk, while using another small...
forums.freebsd.org
And of course the official GELI documentation. I had to step away from the official GELI documentation because it's too difficullt for me to follow.
Both methods mentioned above involve using an unencrypted partition for /boot and an encrypted partition for everything else. However,
1. That's not what I want. If /boot is unencrypted, that is an obvious attack vector. The kernel could be easily tampered with. I want full encryption, EVERYTHING including boot.
2. I have installed FreeBSD with ZFS in the past and it did have full disk encryption, including boot.
So, can it be done with UFS? How?
TIA