<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.osnexus.com/index.php?action=history&amp;feed=atom&amp;title=Encryption_Bypass</id>
	<title>Encryption Bypass - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.osnexus.com/index.php?action=history&amp;feed=atom&amp;title=Encryption_Bypass"/>
	<link rel="alternate" type="text/html" href="https://wiki.osnexus.com/index.php?title=Encryption_Bypass&amp;action=history"/>
	<updated>2026-10-04T09:13:45Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.42.1</generator>
	<entry>
		<id>https://wiki.osnexus.com/index.php?title=Encryption_Bypass&amp;diff=28093&amp;oldid=prev</id>
		<title>Qadmin: Qadmin moved page Ceph Encryption Bypass to Encryption Bypass without leaving a redirect: The feature is not Ceph-specific - the same list governs encrypted scale-up Storage Pools and SED pool devices on the same appliance, so a Ceph-scoped title hides it from scale-up administrators</title>
		<link rel="alternate" type="text/html" href="https://wiki.osnexus.com/index.php?title=Encryption_Bypass&amp;diff=28093&amp;oldid=prev"/>
		<updated>2026-09-04T05:57:33Z</updated>

		<summary type="html">&lt;p&gt;Qadmin moved page &lt;a href=&quot;/index.php?title=Ceph_Encryption_Bypass&quot; class=&quot;mw-redirect&quot; title=&quot;Ceph Encryption Bypass&quot;&gt;Ceph Encryption Bypass&lt;/a&gt; to &lt;a href=&quot;/index.php?title=Encryption_Bypass&quot; title=&quot;Encryption Bypass&quot;&gt;Encryption Bypass&lt;/a&gt; without leaving a redirect: The feature is not Ceph-specific - the same list governs encrypted scale-up Storage Pools and SED pool devices on the same appliance, so a Ceph-scoped title hides it from scale-up administrators&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 05:57, 4 September 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;4&quot; class=&quot;diff-notice&quot; lang=&quot;en&quot;&gt;&lt;div class=&quot;mw-diff-empty&quot;&gt;(No difference)&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;
&lt;!-- diff cache key wikidb:diff:1.41:old-28092:rev-28093 --&gt;
&lt;/table&gt;</summary>
		<author><name>Qadmin</name></author>
	</entry>
	<entry>
		<id>https://wiki.osnexus.com/index.php?title=Encryption_Bypass&amp;diff=28092&amp;oldid=prev</id>
		<title>Qadmin: Correct the framing again per engineering: the bypass is automatic on a vendor:model match - no prompt, no option, the product does the right thing by itself. The previous wording implied a provisioning decision the administrator makes. What actually matters is whether the media is in the list before provisioning, since an unlisted model gets software-encrypted and cannot be converted in place (QSTOR-12352)</title>
		<link rel="alternate" type="text/html" href="https://wiki.osnexus.com/index.php?title=Encryption_Bypass&amp;diff=28092&amp;oldid=prev"/>
		<updated>2026-09-04T05:56:14Z</updated>

		<summary type="html">&lt;p&gt;Correct the framing again per engineering: the bypass is automatic on a vendor:model match - no prompt, no option, the product does the right thing by itself. The previous wording implied a provisioning decision the administrator makes. What actually matters is whether the media is in the list before provisioning, since an unlisted model gets software-encrypted and cannot be converted in place (QSTOR-12352)&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 05:56, 4 September 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l3&quot;&gt;Line 3:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 3:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;The reason is that software encryption does not scale.&amp;#039;&amp;#039;&amp;#039; Wrapping dm-crypt around a device whose array is already encrypting it adds a second encryption layer that costs CPU and throughput on every write while protecting data that is already protected. On a scale-out cluster with many such devices that overhead is significant and buys nothing. In one deployment, reconfiguring a pool from software encryption to bypass took it from roughly &amp;#039;&amp;#039;&amp;#039;500 MB/s to roughly 20 GB/s&amp;#039;&amp;#039;&amp;#039; -- a fortyfold difference on the same hardware, because the array was already doing the encryption and the software layer was simply in the way. Hardware encryption on these arrays can also be enabled &amp;#039;&amp;#039;&amp;#039;at any time, on the fly, without rewriting the data&amp;#039;&amp;#039;&amp;#039; -- so the array&amp;#039;s protection does not have to be arranged before the devices are provisioned, and QuantaStor should stay out of the way either way.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;The reason is that software encryption does not scale.&amp;#039;&amp;#039;&amp;#039; Wrapping dm-crypt around a device whose array is already encrypting it adds a second encryption layer that costs CPU and throughput on every write while protecting data that is already protected. On a scale-out cluster with many such devices that overhead is significant and buys nothing. In one deployment, reconfiguring a pool from software encryption to bypass took it from roughly &amp;#039;&amp;#039;&amp;#039;500 MB/s to roughly 20 GB/s&amp;#039;&amp;#039;&amp;#039; -- a fortyfold difference on the same hardware, because the array was already doing the encryption and the software layer was simply in the way. Hardware encryption on these arrays can also be enabled &amp;#039;&amp;#039;&amp;#039;at any time, on the fly, without rewriting the data&amp;#039;&amp;#039;&amp;#039; -- so the array&amp;#039;s protection does not have to be arranged before the devices are provisioned, and QuantaStor should stay out of the way either way.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&#039;&#039;&#039;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Decide this &lt;/del&gt;before &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;you provision&lt;/del&gt;.&#039;&#039;&#039; &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;The &lt;/del&gt;encryption choice is fixed for the life of an OSD or pool device&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;. An OSD built while an entry is in force cannot be encrypted afterwards&lt;/del&gt;, &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;and -- the costly direction -- &lt;/del&gt;a device already carrying &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;QuantaStor&#039;s &lt;/del&gt;software encryption cannot be switched to bypass in place. &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Converting an existing software-encrypted pool &lt;/del&gt;means &#039;&#039;&#039;copying all of the data off, rebuilding the devices &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;with &lt;/del&gt;the entry in place, and copying it back&#039;&#039;&#039;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;. That is a &lt;/del&gt;lengthy&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;, &lt;/del&gt;disruptive &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;exercise &lt;/del&gt;on a populated cluster&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;, so check &lt;/del&gt;the &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;bypass &lt;/del&gt;list against your media before the &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;first OSD &lt;/del&gt;is &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;created rather than after&lt;/del&gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&#039;&#039;&#039;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;The bypass is automatic -- there is no prompt and no option.&#039;&#039;&#039; If a device&#039;s vendor and model match an entry, QuantaStor skips its own encryption for that device. Nothing asks you to confirm it and there is no checkbox to set: on a match, the product does the right thing on its own. So there is no decision to get wrong at provisioning time, and nothing to remember to switch on.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&#039;&#039;What matters is whether your media is in the list &lt;/ins&gt;before &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;the first device is provisioned&lt;/ins&gt;.&#039;&#039;&#039; &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;A model that is not listed gets QuantaStor&#039;s software encryption, because the appliance has no way to know the array is already encrypting. And that is the expensive situation to discover later: the &lt;/ins&gt;encryption choice is fixed for the life of an OSD or pool device, &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;so &lt;/ins&gt;a device already carrying software encryption cannot be switched to bypass in place. &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Correcting it &lt;/ins&gt;means &#039;&#039;&#039;copying all of the data off, rebuilding the devices &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;once &lt;/ins&gt;the entry &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;is &lt;/ins&gt;in place, and copying it back&#039;&#039;&#039; &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;-- &lt;/ins&gt;lengthy &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;and &lt;/ins&gt;disruptive on a populated cluster&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;. Check &lt;/ins&gt;the list against your media before &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;you provision, and add &lt;/ins&gt;the &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;entry if it &lt;/ins&gt;is &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;missing&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Adding new entries is expected.&amp;#039;&amp;#039;&amp;#039; The file exists so that new vendor and model combinations can be recognised as they are released, without waiting for a QuantaStor update. If you deploy an array that encrypts at rest in hardware and its model is not in the list, adding it is the intended action.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Adding new entries is expected.&amp;#039;&amp;#039;&amp;#039; The file exists so that new vendor and model combinations can be recognised as they are released, without waiting for a QuantaStor update. If you deploy an array that encrypts at rest in hardware and its model is not in the list, adding it is the intended action.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Qadmin</name></author>
	</entry>
	<entry>
		<id>https://wiki.osnexus.com/index.php?title=Encryption_Bypass&amp;diff=28091&amp;oldid=prev</id>
		<title>Qadmin: Add the measured impact from a real deployment - a pool reconfigured from software encryption to bypass went from ~500 MB/s to ~20 GB/s on the same hardware - and a prominent warning that the choice must be made before provisioning, because converting an existing software-encrypted pool requires copying all the data off and rebuilding the devices (QSTOR-12352)</title>
		<link rel="alternate" type="text/html" href="https://wiki.osnexus.com/index.php?title=Encryption_Bypass&amp;diff=28091&amp;oldid=prev"/>
		<updated>2026-09-04T05:53:49Z</updated>

		<summary type="html">&lt;p&gt;Add the measured impact from a real deployment - a pool reconfigured from software encryption to bypass went from ~500 MB/s to ~20 GB/s on the same hardware - and a prominent warning that the choice must be made before provisioning, because converting an existing software-encrypted pool requires copying all the data off and rebuilding the devices (QSTOR-12352)&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 05:53, 4 September 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The &amp;#039;&amp;#039;&amp;#039;encryption bypass&amp;#039;&amp;#039;&amp;#039; list tells QuantaStor not to apply its own software encryption to devices that are &amp;#039;&amp;#039;&amp;#039;already encrypted by the storage system presenting them&amp;#039;&amp;#039;&amp;#039;. Arrays such as the Seagate Corvault, Seagate Exos E/EP and Dell PowerVault families encrypt at rest in hardware and present logical devices to the appliance. For media like these, bypass is not an exception to normal practice -- &amp;#039;&amp;#039;&amp;#039;it is the correct configuration&amp;#039;&amp;#039;&amp;#039;, and it is what the shipped file already does for the models listed in it.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The &amp;#039;&amp;#039;&amp;#039;encryption bypass&amp;#039;&amp;#039;&amp;#039; list tells QuantaStor not to apply its own software encryption to devices that are &amp;#039;&amp;#039;&amp;#039;already encrypted by the storage system presenting them&amp;#039;&amp;#039;&amp;#039;. Arrays such as the Seagate Corvault, Seagate Exos E/EP and Dell PowerVault families encrypt at rest in hardware and present logical devices to the appliance. For media like these, bypass is not an exception to normal practice -- &amp;#039;&amp;#039;&amp;#039;it is the correct configuration&amp;#039;&amp;#039;&amp;#039;, and it is what the shipped file already does for the models listed in it.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&#039;&#039;&#039;The reason is that software encryption does not scale.&#039;&#039;&#039; Wrapping dm-crypt around a device whose array is already encrypting it adds a second encryption layer that costs CPU and throughput on every write while protecting data that is already protected. On a scale-out cluster with many such devices that overhead is significant and buys nothing. Hardware encryption on these arrays can also be enabled &#039;&#039;&#039;at any time, on the fly, without rewriting the data&#039;&#039;&#039; -- so the array&#039;s protection does not have to be arranged before the devices are provisioned, and QuantaStor should stay out of the way either way.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&#039;&#039;&#039;The reason is that software encryption does not scale.&#039;&#039;&#039; Wrapping dm-crypt around a device whose array is already encrypting it adds a second encryption layer that costs CPU and throughput on every write while protecting data that is already protected. On a scale-out cluster with many such devices that overhead is significant and buys nothing&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;. In one deployment, reconfiguring a pool from software encryption to bypass took it from roughly &#039;&#039;&#039;500 MB/s to roughly 20 GB/s&#039;&#039;&#039; -- a fortyfold difference on the same hardware, because the array was already doing the encryption and the software layer was simply in the way&lt;/ins&gt;. Hardware encryption on these arrays can also be enabled &#039;&#039;&#039;at any time, on the fly, without rewriting the data&#039;&#039;&#039; -- so the array&#039;s protection does not have to be arranged before the devices are provisioned, and QuantaStor should stay out of the way either way&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&#039;&#039;Decide this before you provision.&#039;&#039;&#039; The encryption choice is fixed for the life of an OSD or pool device. An OSD built while an entry is in force cannot be encrypted afterwards, and -- the costly direction -- a device already carrying QuantaStor&#039;s software encryption cannot be switched to bypass in place. Converting an existing software-encrypted pool means &#039;&#039;&#039;copying all of the data off, rebuilding the devices with the entry in place, and copying it back&#039;&#039;&#039;. That is a lengthy, disruptive exercise on a populated cluster, so check the bypass list against your media before the first OSD is created rather than after&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Adding new entries is expected.&amp;#039;&amp;#039;&amp;#039; The file exists so that new vendor and model combinations can be recognised as they are released, without waiting for a QuantaStor update. If you deploy an array that encrypts at rest in hardware and its model is not in the list, adding it is the intended action.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Adding new entries is expected.&amp;#039;&amp;#039;&amp;#039; The file exists so that new vendor and model combinations can be recognised as they are released, without waiting for a QuantaStor update. If you deploy an array that encrypts at rest in hardware and its model is not in the list, adding it is the intended action.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Qadmin</name></author>
	</entry>
	<entry>
		<id>https://wiki.osnexus.com/index.php?title=Encryption_Bypass&amp;diff=28090&amp;oldid=prev</id>
		<title>Qadmin: Correct the framing per engineering: bypass is the intended configuration for arrays that encrypt at rest in hardware (Seagate Corvault, Seagate Exos E/EP, Dell PowerVault and similar), not a security exception to be avoided. Adds the rationale - software encryption does not scale and a second layer over already-encrypted media costs throughput for no gain - notes that hardware encryption on these arrays can be enabled on the fly without rewriting data, and states that adding new vendor:model...</title>
		<link rel="alternate" type="text/html" href="https://wiki.osnexus.com/index.php?title=Encryption_Bypass&amp;diff=28090&amp;oldid=prev"/>
		<updated>2026-09-04T05:53:05Z</updated>

		<summary type="html">&lt;p&gt;Correct the framing per engineering: bypass is the intended configuration for arrays that encrypt at rest in hardware (Seagate Corvault, Seagate Exos E/EP, Dell PowerVault and similar), not a security exception to be avoided. Adds the rationale - software encryption does not scale and a second layer over already-encrypted media costs throughput for no gain - notes that hardware encryption on these arrays can be enabled on the fly without rewriting data, and states that adding new vendor:model...&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 05:53, 4 September 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The &#039;&#039;&#039;encryption bypass&#039;&#039;&#039; list &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;excludes a device type from &lt;/del&gt;QuantaStor&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;s data-at-rest &lt;/del&gt;encryption&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;. A device &lt;/del&gt;that &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;matches an entry is provisioned into an encryption-enabled Ceph cluster -- or an encrypted [[Storage Pools|Storage Pool]] -- &lt;/del&gt;&#039;&#039;&#039;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;without being &lt;/del&gt;encrypted by &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;QuantaStor&lt;/del&gt;&#039;&#039;&#039;. &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;The data lands in the clear as far &lt;/del&gt;as the &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;appliance is concerned&lt;/del&gt;, and &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;protecting it &lt;/del&gt;at rest &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;is left entirely &lt;/del&gt;to the media&#039;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;s own hardware encryption. The feature exists for self-encrypting storage such as &lt;/del&gt;the &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Seagate Corvault enclosures&lt;/del&gt;, &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;whose LUNs &lt;/del&gt;already &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;encrypt at rest and gain nothing from a second software layer wrapped around them&lt;/del&gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The &#039;&#039;&#039;encryption bypass&#039;&#039;&#039; list &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;tells &lt;/ins&gt;QuantaStor &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;not to apply its own software &lt;/ins&gt;encryption &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;to devices &lt;/ins&gt;that &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;are &lt;/ins&gt;&#039;&#039;&#039;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;already &lt;/ins&gt;encrypted by &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;the storage system presenting them&lt;/ins&gt;&#039;&#039;&#039;. &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Arrays such &lt;/ins&gt;as the &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Seagate Corvault&lt;/ins&gt;, &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Seagate Exos E/EP &lt;/ins&gt;and &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Dell PowerVault families encrypt &lt;/ins&gt;at rest &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;in hardware and present logical devices &lt;/ins&gt;to the &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;appliance. For &lt;/ins&gt;media &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;like these, bypass is not an exception to normal practice -- &#039;&#039;&lt;/ins&gt;&#039;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;it is &lt;/ins&gt;the &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;correct configuration&#039;&#039;&#039;&lt;/ins&gt;, &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;and it is what the shipped file &lt;/ins&gt;already &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;does for the models listed in it&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&#039;&#039;&#039;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;This &lt;/del&gt;is a &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;security exception mechanism&lt;/del&gt;, not &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;a performance option&lt;/del&gt;.&#039;&#039;&#039; &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;An &lt;/del&gt;entry &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;turns QuantaStor&lt;/del&gt;&#039;s encryption &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;off &lt;/del&gt;for &#039;&#039;&#039;every&#039;&#039;&#039; device of that vendor and model on the node, and &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;for any &lt;/del&gt;OSD created while the entry is in force &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;the exception is permanent -- there is no way to encrypt that OSD afterwards &lt;/del&gt;without destroying and re-creating it&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;. The two Seagate Corvault entries that ship in the file are the supported use of it. We recommend adding an entry only when OSNEXUS support has asked you to, and only for media you have established encrypts at rest on its own&lt;/del&gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&#039;&#039;&#039;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;The reason &lt;/ins&gt;is &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;that software encryption does not scale.&#039;&#039;&#039; Wrapping dm-crypt around &lt;/ins&gt;a &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;device whose array is already encrypting it adds a second encryption layer that costs CPU and throughput on every write while protecting data that is already protected. On a scale-out cluster with many such devices that overhead is significant and buys nothing. Hardware encryption on these arrays can also be enabled &#039;&#039;&#039;at any time, on the fly&lt;/ins&gt;, &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;without rewriting the data&#039;&#039;&#039; -- so the array&#039;s protection does &lt;/ins&gt;not &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;have to be arranged before the devices are provisioned, and QuantaStor should stay out of the way either way.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&#039;&#039;Adding new entries is expected&lt;/ins&gt;.&#039;&#039;&#039; &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;The file exists so that new vendor and model combinations can be recognised as they are released, without waiting for a QuantaStor update. If you deploy an array that encrypts at rest in hardware and its model is not in the list, adding it is the intended action.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;What the list does require is that the claim be true. QuantaStor cannot verify that a device encrypts itself; it takes the &lt;/ins&gt;entry&#039;s &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;word for it and skips its own &lt;/ins&gt;encryption&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;. So add an entry only &lt;/ins&gt;for &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;media you have established encrypts at rest, and note that an entry matches &lt;/ins&gt;&#039;&#039;&#039;every&#039;&#039;&#039; device of that vendor and model on the node, and &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;that an &lt;/ins&gt;OSD created while the entry is in force &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;cannot be encrypted later &lt;/ins&gt;without destroying and re-creating it.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;There is no dialog for this list and no &amp;lt;code&amp;gt;qs&amp;lt;/code&amp;gt; command that edits it. It is a per-node configuration file, read once when the QuantaStor service starts.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;There is no dialog for this list and no &amp;lt;code&amp;gt;qs&amp;lt;/code&amp;gt; command that edits it. It is a per-node configuration file, read once when the QuantaStor service starts.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l166&quot;&gt;Line 166:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 170:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Security consequences ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Security consequences ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Stated without hedging&lt;/del&gt;, &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;because &lt;/del&gt;the &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;point &lt;/del&gt;of &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;the feature is to switch protection off&lt;/del&gt;:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Bypass is the right configuration for hardware-encrypted media&lt;/ins&gt;, &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;but it moves responsibility for data-at-rest protection off &lt;/ins&gt;the &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;appliance entirely. The consequences &lt;/ins&gt;of &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;that, stated plainly&lt;/ins&gt;:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &#039;&#039;&#039;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;The data &lt;/del&gt;is &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;in the clear on the medium&lt;/del&gt;.&#039;&#039;&#039; A bypassed block device holds plaintext BlueStore data&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;. A drive pulled from &lt;/del&gt;the &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;chassis &lt;/del&gt;is &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;readable unless &lt;/del&gt;the &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;hardware&#039;s own encryption stops it&lt;/del&gt;, and QuantaStor has no way to &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;confirm that &lt;/del&gt;it &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;does&lt;/del&gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &#039;&#039;&#039;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;QuantaStor writes plaintext, and cannot confirm the array &lt;/ins&gt;is &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;encrypting&lt;/ins&gt;.&#039;&#039;&#039; A bypassed block device holds plaintext BlueStore data &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;as far as &lt;/ins&gt;the &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;appliance &lt;/ins&gt;is &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;concerned. Protection at rest depends wholly on &lt;/ins&gt;the &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;array&lt;/ins&gt;, and QuantaStor has no way to &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;verify &lt;/ins&gt;it &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;is switched on -- so if the array&#039;s encryption is disabled, or was never enabled, nothing on the appliance will report the data as unprotected&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &#039;&#039;&#039;An audit of the cluster will not show the exception.&#039;&#039;&#039; The cluster remains an encryption-enabled cluster, the OSD remains &amp;lt;code&amp;gt;ceph.encrypted=1&amp;lt;/code&amp;gt;, and the &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;WUI &lt;/del&gt;reports the cluster as encrypted. Only the configuration file, the service log and the LVM tag reveal that a device is excluded.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &#039;&#039;&#039;An audit of the cluster will not show the exception.&#039;&#039;&#039; The cluster remains an encryption-enabled cluster, the OSD remains &amp;lt;code&amp;gt;ceph.encrypted=1&amp;lt;/code&amp;gt;, and the &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;interface &lt;/ins&gt;reports the cluster as encrypted. Only the configuration file, the service log and the LVM tag reveal that a device is excluded&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;, so anyone auditing encryption coverage needs to read the bypass list too&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &#039;&#039;&#039;The scope is the device model, not the device.&#039;&#039;&#039; Every matching device on the node is excluded, including devices added later.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &#039;&#039;&#039;The scope is the device model, not the device.&#039;&#039;&#039; Every matching device on the node is excluded, including devices added later&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;. That is what makes the feature practical for a large array, and it also means an entry cannot be narrowed to a single drive&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &#039;&#039;&#039;The scope is &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;also &lt;/del&gt;not limited to Ceph.&#039;&#039;&#039; The same list governs encrypted Storage Pools and SED pool devices on the same appliance. An entry added &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;to allow &lt;/del&gt;a Corvault OSD also &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;disables encryption for &lt;/del&gt;Corvault LUNs used in a Storage Pool on that node.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &#039;&#039;&#039;The scope is not limited to Ceph.&#039;&#039;&#039; The same list governs encrypted Storage Pools and SED pool devices on the same appliance. An entry added &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;for &lt;/ins&gt;a Corvault OSD also &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;applies to &lt;/ins&gt;Corvault LUNs used in a Storage Pool on that node &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;-- usually what you want, since the array encrypts either way, but worth knowing it is one list&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &#039;&#039;&#039;Key rotation &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;silently &lt;/del&gt;skips bypassed OSDs.&#039;&#039;&#039; A &amp;lt;code&amp;gt;qs ceph-osd-key-replace&amp;lt;/code&amp;gt; run reports success while leaving matching OSDs untouched, because there is no key to replace.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &#039;&#039;&#039;Key rotation skips bypassed OSDs.&#039;&#039;&#039; A &amp;lt;code&amp;gt;qs ceph-osd-key-replace&amp;lt;/code&amp;gt; run reports success while leaving matching OSDs untouched, because there is no &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;QuantaStor-held &lt;/ins&gt;key to replace&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;. Key rotation for these devices is the array&#039;s business&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &#039;&#039;&#039;Health monitoring is reduced.&#039;&#039;&#039; Matching devices are excluded from SMART and temperature collection, so drive-health alerting &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;for them &lt;/del&gt;comes from the enclosure rather than from QuantaStor.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &#039;&#039;&#039;Health monitoring is reduced.&#039;&#039;&#039; Matching devices are excluded from SMART and temperature collection, so drive-health alerting comes from the enclosure rather than from QuantaStor.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Interaction with Storage Pools and SED media ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Interaction with Storage Pools and SED media ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key wikidb:diff:1.41:old-27728:rev-28090:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>Qadmin</name></author>
	</entry>
	<entry>
		<id>https://wiki.osnexus.com/index.php?title=Encryption_Bypass&amp;diff=27728&amp;oldid=prev</id>
		<title>Qadmin: Restore the systemd Services related link carried by the previous revision (QSTOR-12352)</title>
		<link rel="alternate" type="text/html" href="https://wiki.osnexus.com/index.php?title=Encryption_Bypass&amp;diff=27728&amp;oldid=prev"/>
		<updated>2026-09-03T11:23:26Z</updated>

		<summary type="html">&lt;p&gt;Restore the systemd Services related link carried by the previous revision (QSTOR-12352)&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 11:23, 3 September 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l209&quot;&gt;Line 209:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 209:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [[Seagate Corvault Configuration]] -- the hardware the shipped entries exist for&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [[Seagate Corvault Configuration]] -- the hardware the shipped entries exist for&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [[Security Configuration]] -- appliance-wide security settings&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [[Security Configuration]] -- appliance-wide security settings&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* [[QuantaStor systemd Services]] -- the service and the boot units named above&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;----&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;----&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Qadmin</name></author>
	</entry>
	<entry>
		<id>https://wiki.osnexus.com/index.php?title=Encryption_Bypass&amp;diff=27727&amp;oldid=prev</id>
		<title>Qadmin: Clarify where the ceph-volume activation message is logged (QSTOR-12352)</title>
		<link rel="alternate" type="text/html" href="https://wiki.osnexus.com/index.php?title=Encryption_Bypass&amp;diff=27727&amp;oldid=prev"/>
		<updated>2026-09-03T11:23:02Z</updated>

		<summary type="html">&lt;p&gt;Clarify where the ceph-volume activation message is logged (QSTOR-12352)&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 11:23, 3 September 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l150&quot;&gt;Line 150:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 150:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# &amp;#039;&amp;#039;&amp;#039;The absence of a crypt layer.&amp;#039;&amp;#039;&amp;#039; &amp;lt;code&amp;gt;lsblk&amp;lt;/code&amp;gt; on the bypassed device shows the LVM layer with no &amp;lt;code&amp;gt;crypt&amp;lt;/code&amp;gt; device above the block LV, while the WAL and DB LVs of the same OSD still show one.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# &amp;#039;&amp;#039;&amp;#039;The absence of a crypt layer.&amp;#039;&amp;#039;&amp;#039; &amp;lt;code&amp;gt;lsblk&amp;lt;/code&amp;gt; on the bypassed device shows the LVM layer with no &amp;lt;code&amp;gt;crypt&amp;lt;/code&amp;gt; device above the block LV, while the WAL and DB LVs of the same OSD still show one.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;During OSD creation, &amp;lt;code&amp;gt;ceph-volume&amp;lt;/code&amp;gt; also logs &amp;lt;code&amp;gt;Skipping block device encryption for: &amp;amp;lt;path&amp;amp;gt;&amp;lt;/code&amp;gt;, and on activation &amp;lt;code&amp;gt;Skipping block device decryption for &amp;amp;lt;path&amp;amp;gt;&amp;lt;/code&amp;gt;. &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Both land &lt;/del&gt;in the QuantaStor service log with the rest of the OSD creation output.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;During OSD creation, &amp;lt;code&amp;gt;ceph-volume&amp;lt;/code&amp;gt; also logs &amp;lt;code&amp;gt;Skipping block device encryption for: &amp;amp;lt;path&amp;amp;gt;&amp;lt;/code&amp;gt;, and on activation &amp;lt;code&amp;gt;Skipping block device decryption for &amp;amp;lt;path&amp;amp;gt;&amp;lt;/code&amp;gt;. &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;The creation message lands &lt;/ins&gt;in the QuantaStor service log with the rest of the OSD creation output&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;; the activation message goes wherever the activation ran -- the service log when QuantaStor drove it, the systemd journal for the &amp;lt;code&amp;gt;ceph-volume@&amp;lt;/code&amp;gt; unit when the node activated its OSDs at boot&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Reversing it ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Reversing it ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Qadmin</name></author>
	</entry>
	<entry>
		<id>https://wiki.osnexus.com/index.php?title=Encryption_Bypass&amp;diff=27725&amp;oldid=prev</id>
		<title>Qadmin: Rewrite from the product: correct the match key (SCSI vendor + product ID, not device path/serial), document what the bypass actually skips per encryption mode, the WAL/DB devices staying encrypted, the ceph.block_skip_enc LVM tag, override-file handling, when the list is re-evaluated, verification, reversal and security consequences; drop invented qs physical-disk-get and qs-util restartmgmt commands; fix categories (QSTOR-12352)</title>
		<link rel="alternate" type="text/html" href="https://wiki.osnexus.com/index.php?title=Encryption_Bypass&amp;diff=27725&amp;oldid=prev"/>
		<updated>2026-09-03T11:20:29Z</updated>

		<summary type="html">&lt;p&gt;Rewrite from the product: correct the match key (SCSI vendor + product ID, not device path/serial), document what the bypass actually skips per encryption mode, the WAL/DB devices staying encrypted, the ceph.block_skip_enc LVM tag, override-file handling, when the list is re-evaluated, verification, reversal and security consequences; drop invented qs physical-disk-get and qs-util restartmgmt commands; fix categories (QSTOR-12352)&lt;/p&gt;
&lt;a href=&quot;https://wiki.osnexus.com/index.php?title=Encryption_Bypass&amp;amp;diff=27725&amp;amp;oldid=27169&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>Qadmin</name></author>
	</entry>
	<entry>
		<id>https://wiki.osnexus.com/index.php?title=Encryption_Bypass&amp;diff=27169&amp;oldid=prev</id>
		<title>Qadmin: Create Ceph Encryption Bypass admin page (per-device encryption exceptions)</title>
		<link rel="alternate" type="text/html" href="https://wiki.osnexus.com/index.php?title=Encryption_Bypass&amp;diff=27169&amp;oldid=prev"/>
		<updated>2026-06-18T22:40:02Z</updated>

		<summary type="html">&lt;p&gt;Create Ceph Encryption Bypass admin page (per-device encryption exceptions)&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;= Ceph Encryption Bypass (Per-Device Encryption Exceptions) =&lt;br /&gt;
&lt;br /&gt;
The &amp;#039;&amp;#039;&amp;#039;Ceph Encryption Bypass&amp;#039;&amp;#039;&amp;#039; feature lets you exclude specific device&lt;br /&gt;
types from QuantaStor&amp;#039;s data-at-rest encryption when those devices already&lt;br /&gt;
provide their own encryption. It is used when building OSDs on an&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;encryption-enabled Ceph cluster&amp;#039;&amp;#039;&amp;#039; that contains drives or enclosures&lt;br /&gt;
which encrypt data internally — most commonly self-encrypting storage&lt;br /&gt;
arrays such as the &amp;#039;&amp;#039;&amp;#039;Seagate Corvault&amp;#039;&amp;#039;&amp;#039; family.&lt;br /&gt;
&lt;br /&gt;
Without this feature, every OSD on an encryption-enabled cluster is wrapped&lt;br /&gt;
in QuantaStor&amp;#039;s software (dmcrypt/LUKS) or SED encryption. For media that is&lt;br /&gt;
already self-encrypting that produces redundant &amp;quot;double encryption&amp;quot;, which&lt;br /&gt;
adds CPU and latency overhead and complicates key management with no&lt;br /&gt;
additional security benefit. The encryption bypass list tells QuantaStor to&lt;br /&gt;
create the OSD in the encrypted cluster &amp;#039;&amp;#039;&amp;#039;but skip the encryption layer for&lt;br /&gt;
that one device&amp;#039;&amp;#039;&amp;#039;, trusting the hardware to protect data at rest.&lt;br /&gt;
&lt;br /&gt;
{{Note|The bypass only takes effect on Ceph clusters/OSDs that were created&lt;br /&gt;
with encryption enabled. On an unencrypted cluster it has no effect — nothing&lt;br /&gt;
is encrypted in the first place.}}&lt;br /&gt;
&lt;br /&gt;
== When to use it ==&lt;br /&gt;
&lt;br /&gt;
Add a device to the bypass list when &amp;#039;&amp;#039;&amp;#039;all&amp;#039;&amp;#039;&amp;#039; of the following are true:&lt;br /&gt;
&lt;br /&gt;
* You are deploying Ceph OSDs on a cluster created with encryption enabled (software dmcrypt/LUKS or SED).&lt;br /&gt;
* The target media (drive, or the LUNs presented by a self-encrypting enclosure) performs its own data-at-rest encryption in hardware.&lt;br /&gt;
* You want the device&amp;#039;s hardware encryption — not QuantaStor&amp;#039;s — to be the encryption-at-rest mechanism for those OSDs.&lt;br /&gt;
&lt;br /&gt;
Typical examples:&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Seagate Corvault&amp;#039;&amp;#039;&amp;#039; self-encrypting enclosures (4U106 and 5U84), which are pre-configured in the bypass list out of the box.&lt;br /&gt;
* Other vendor arrays/drives with always-on internal encryption that you have validated meet your data-at-rest requirements.&lt;br /&gt;
&lt;br /&gt;
== How it works ==&lt;br /&gt;
&lt;br /&gt;
# When QuantaStor creates a Bluestore OSD on an encryption-enabled cluster, it looks up the OSD&amp;#039;s underlying device by &amp;#039;&amp;#039;&amp;#039;SCSI Vendor ID&amp;#039;&amp;#039;&amp;#039; and &amp;#039;&amp;#039;&amp;#039;Product (Model) ID&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
# If that Vendor/Model pair appears in the encryption bypass list, the device is treated as an &amp;#039;&amp;#039;&amp;#039;encryption exception&amp;#039;&amp;#039;&amp;#039;:&lt;br /&gt;
#* On a &amp;#039;&amp;#039;&amp;#039;software (dmcrypt/LUKS)&amp;#039;&amp;#039;&amp;#039; cluster, the OSD is still created as part of the encrypted cluster, but the data device is provisioned with &amp;lt;code&amp;gt;--block.skip-enc&amp;lt;/code&amp;gt; so its block device is not LUKS-encrypted.&lt;br /&gt;
#* On an &amp;#039;&amp;#039;&amp;#039;SED&amp;#039;&amp;#039;&amp;#039; cluster, the device is not crypt-formatted by QuantaStor; the drive&amp;#039;s self-encryption is relied upon instead.&lt;br /&gt;
# Devices &amp;#039;&amp;#039;&amp;#039;not&amp;#039;&amp;#039;&amp;#039; in the list are encrypted normally — the bypass is strictly opt-in, per Vendor/Model.&lt;br /&gt;
&lt;br /&gt;
The matching is by Vendor + Model string only, so a single entry covers&lt;br /&gt;
every drive/LUN of that type across the cluster.&lt;br /&gt;
&lt;br /&gt;
== Configuration ==&lt;br /&gt;
&lt;br /&gt;
The bypass list is a per-node configuration file:&lt;br /&gt;
&lt;br /&gt;
 /opt/osnexus/quantastor/conf/qs_encryption_bypass.conf&lt;br /&gt;
&lt;br /&gt;
It is an INI-style file. Each entry is a named section with a&lt;br /&gt;
&amp;lt;code&amp;gt;vendor&amp;lt;/code&amp;gt; and a &amp;lt;code&amp;gt;model&amp;lt;/code&amp;gt; key that must match the device&amp;#039;s&lt;br /&gt;
SCSI Vendor ID and Product ID exactly (case-sensitive):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Seagate Corvault systems have built-in encryption, so QuantaStor&amp;#039;s&lt;br /&gt;
# software/SED encryption is bypassed for these devices.&lt;br /&gt;
[seagate_corvault_4u106]&lt;br /&gt;
vendor=SEAGATE&lt;br /&gt;
model=6575&lt;br /&gt;
&lt;br /&gt;
[seagate_corvault_5u84]&lt;br /&gt;
vendor=SEAGATE&lt;br /&gt;
model=6566&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To add a new device type:&lt;br /&gt;
&lt;br /&gt;
# Determine the device&amp;#039;s SCSI &amp;#039;&amp;#039;&amp;#039;Vendor ID&amp;#039;&amp;#039;&amp;#039; and &amp;#039;&amp;#039;&amp;#039;Product/Model ID&amp;#039;&amp;#039;&amp;#039;. You can read these from:&lt;br /&gt;
#* The WUI — &amp;#039;&amp;#039;&amp;#039;Physical Disks/Devices&amp;#039;&amp;#039;&amp;#039; → disk properties (Vendor / Model fields).&lt;br /&gt;
#* The CLI — &amp;lt;code&amp;gt;qs physical-disk-get &amp;lt;disk&amp;gt;&amp;lt;/code&amp;gt;.&lt;br /&gt;
#* The shell — &amp;lt;code&amp;gt;lsscsi -v&amp;lt;/code&amp;gt;, or &amp;lt;code&amp;gt;sg_inq /dev/sdX&amp;lt;/code&amp;gt; (Vendor identification / Product identification).&lt;br /&gt;
# Add a new section to &amp;lt;code&amp;gt;qs_encryption_bypass.conf&amp;lt;/code&amp;gt; with the matching &amp;lt;code&amp;gt;vendor=&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;model=&amp;lt;/code&amp;gt; values.&lt;br /&gt;
# Repeat the edit on &amp;#039;&amp;#039;&amp;#039;every Ceph node&amp;#039;&amp;#039;&amp;#039; that will host OSDs of that device type. This file is &amp;#039;&amp;#039;&amp;#039;not&amp;#039;&amp;#039;&amp;#039; grid-synced — it is a local, per-node configuration that you must update manually on each node.&lt;br /&gt;
# Restart the QuantaStor service so the list is reloaded: &amp;lt;code&amp;gt;systemctl restart quantastor&amp;lt;/code&amp;gt; (or &amp;lt;code&amp;gt;qs-util restartmgmt&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
{{Note|Add the device to the bypass list &amp;#039;&amp;#039;&amp;#039;before&amp;#039;&amp;#039;&amp;#039; creating the OSDs you&lt;br /&gt;
want excluded. Existing OSDs are not retroactively re-encrypted or&lt;br /&gt;
de-encrypted when the list changes — the bypass is evaluated at OSD-creation&lt;br /&gt;
time.}}&lt;br /&gt;
&lt;br /&gt;
== ceph-volume patch dependency ==&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;--block.skip-enc&amp;lt;/code&amp;gt; option used on software-encrypted clusters&lt;br /&gt;
is a QuantaStor extension to the stock Ceph &amp;lt;code&amp;gt;ceph-volume&amp;lt;/code&amp;gt; tool.&lt;br /&gt;
QuantaStor maintains this patch automatically and admins do not normally need&lt;br /&gt;
to interact with it:&lt;br /&gt;
&lt;br /&gt;
* The patch is &amp;#039;&amp;#039;&amp;#039;idempotent and version-aware&amp;#039;&amp;#039;&amp;#039; — safe to re-run, and it only applies the patch set matching the running Ceph release.&lt;br /&gt;
* It is re-applied automatically at QuantaStor service start, after any &amp;lt;code&amp;gt;apt&amp;lt;/code&amp;gt; operation that may have reinstalled/upgraded &amp;lt;code&amp;gt;ceph-volume&amp;lt;/code&amp;gt;, and on boot before any OSD is activated.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Fail-safe by design:&amp;#039;&amp;#039;&amp;#039; if the patch cannot be applied to the running &amp;lt;code&amp;gt;ceph-volume&amp;lt;/code&amp;gt; (for example after an unexpected Ceph point-release change), QuantaStor logs a loud patch-failure error and the OSD operation fails rather than silently mis-encrypting data. If you see such an alert, contact OSNexus support before forcing OSD creation.&lt;br /&gt;
&lt;br /&gt;
To temporarily disable the ceph-volume patching (advanced/support use only),&lt;br /&gt;
create the disable touchfile on the affected node:&lt;br /&gt;
&lt;br /&gt;
 /var/opt/osnexus/quantastor/touchfiles/tf_qs_ceph_volume_patch.disable&lt;br /&gt;
&lt;br /&gt;
While this touchfile is present, the patch is not applied and&lt;br /&gt;
encryption-bypass OSD creation on software-encrypted clusters will fail.&lt;br /&gt;
Remove the touchfile and restart the service to re-enable.&lt;br /&gt;
&lt;br /&gt;
== Verifying ==&lt;br /&gt;
&lt;br /&gt;
After creating OSDs on a bypassed device type:&lt;br /&gt;
&lt;br /&gt;
* Confirm the OSDs come &amp;#039;&amp;#039;&amp;#039;up/in&amp;#039;&amp;#039;&amp;#039; normally (WUI Ceph view, or &amp;lt;code&amp;gt;ceph osd tree&amp;lt;/code&amp;gt;).&lt;br /&gt;
* On a software-encrypted cluster, confirm the bypassed device&amp;#039;s data block device is &amp;#039;&amp;#039;&amp;#039;not&amp;#039;&amp;#039;&amp;#039; a LUKS/dmcrypt device (e.g. &amp;lt;code&amp;gt;lsblk&amp;lt;/code&amp;gt; shows no &amp;lt;code&amp;gt;crypt&amp;lt;/code&amp;gt; layer on it), while non-bypassed OSDs on the same cluster still show the encrypted layer.&lt;br /&gt;
* Review &amp;lt;code&amp;gt;/var/log/qs/ceph_volume_patch.log&amp;lt;/code&amp;gt; and the QuantaStor service log if you need to confirm the ceph-volume patch applied cleanly.&lt;br /&gt;
&lt;br /&gt;
== See also ==&lt;br /&gt;
&lt;br /&gt;
* [[Create Ceph Cluster Configuration]]&lt;br /&gt;
* [[Physical Disks/Devices]]&lt;br /&gt;
* [[Security Configuration]]&lt;br /&gt;
* [[QuantaStor systemd Services]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Administrator Guide]]&lt;br /&gt;
[[Category:Scale-out Storage (Ceph)]]&lt;br /&gt;
[[Category:Encryption]]&lt;/div&gt;</summary>
		<author><name>Qadmin</name></author>
	</entry>
</feed>