Encryption Bypass: Revision history

Jump to navigation Jump to search

Diff selection: Mark the radio buttons of the revisions to compare and hit enter or the button at the bottom.
Legend: (cur) = difference with latest revision, (prev) = difference with preceding revision, m = minor edit.

4 September 2026

  • curprev 05:5705:57, 4 September 2026‎ Qadmin talk contribs‎ m 21,868 bytes 0‎ Qadmin moved page Ceph Encryption Bypass to Encryption Bypass without leaving a redirect: The feature is not Ceph-specific - the same list governs encrypted scale-up Storage Pools and SED pool devices on the same appliance, so a Ceph-scoped title hides it from scale-up administrators
  • curprev 05:5605:56, 4 September 2026‎ Qadmin talk contribs‎ m 21,868 bytes +477‎ Correct the framing again per engineering: the bypass is automatic on a vendor:model match - no prompt, no option, the product does the right thing by itself. The previous wording implied a provisioning decision the administrator makes. What actually matters is whether the media is in the list before provisioning, since an unlisted model gets software-encrypted and cannot be converted in place (QSTOR-12352)
  • curprev 05:5305:53, 4 September 2026‎ Qadmin talk contribs‎ m 21,391 bytes +902‎ Add the measured impact from a real deployment - a pool reconfigured from software encryption to bypass went from ~500 MB/s to ~20 GB/s on the same hardware - and a prominent warning that the choice must be made before provisioning, because converting an existing software-encrypted pool requires copying all the data off and rebuilding the devices (QSTOR-12352)
  • curprev 05:5305:53, 4 September 2026‎ Qadmin talk contribs‎ m 20,489 bytes +1,283‎ Correct the framing per engineering: bypass is the intended configuration for arrays that encrypt at rest in hardware (Seagate Corvault, Seagate Exos E/EP, Dell PowerVault and similar), not a security exception to be avoided. Adds the rationale - software encryption does not scale and a second layer over already-encrypted media costs throughput for no gain - notes that hardware encryption on these arrays can be enabled on the fly without rewriting data, and states that adding new vendor:model...

3 September 2026

  • curprev 11:2311:23, 3 September 2026‎ Qadmin talk contribs‎ m 19,206 bytes +80‎ Restore the systemd Services related link carried by the previous revision (QSTOR-12352)
  • curprev 11:2311:23, 3 September 2026‎ Qadmin talk contribs‎ m 19,126 bytes +219‎ Clarify where the ceph-volume activation message is logged (QSTOR-12352)
  • curprev 11:2011:20, 3 September 2026‎ Qadmin talk contribs‎ m 18,907 bytes +12,229‎ Rewrite from the product: correct the match key (SCSI vendor + product ID, not device path/serial), document what the bypass actually skips per encryption mode, the WAL/DB devices staying encrypted, the ceph.block_skip_enc LVM tag, override-file handling, when the list is re-evaluated, verification, reversal and security consequences; drop invented qs physical-disk-get and qs-util restartmgmt commands; fix categories (QSTOR-12352)

18 June 2026