When we encrypt the ZFS disk (whole volume), we need to enter a "passphrase". However, a "master key" is created to encrypt the data. The "passphrase" is the key to unlock the "master key". So, we can change the "passphrase" later and the "master key" remains the same but will be secured by the new "passphrase"; and the encrypted data remains the same because it is encrypted by the same "master key".
So, this leaves me wondering...
First, to be clear: changing the "passphrase" does not change the "master key", and thus will not re-encrypt the data.
It seems that the "passhrase" is not used and not even relavant to the generated of the "master key" to encrypt the data.... is this correct?
And if that is correct... how is the "master key" generated/created?
Could anyone please clarify this?
So, this leaves me wondering...
First, to be clear: changing the "passphrase" does not change the "master key", and thus will not re-encrypt the data.
It seems that the "passhrase" is not used and not even relavant to the generated of the "master key" to encrypt the data.... is this correct?
And if that is correct... how is the "master key" generated/created?
Could anyone please clarify this?