Jump to content

coliny

Members
  • Posts

    10
  • Joined

  • Last visited

Posts posted by coliny

  1. 33 minutes ago, bonienl said:

    unRAID 6.4.0-rc8 will introduce encryption per individual disk based on LUKS. If you have a little patience, try out this latest RC release, it should become available shortly.

    For clarity, will this protect passwords specified in the _configuration_ of a docker. So, for example, the seafile docker requires the administrator's password as a parameter to the docker, so it is entered in plaintext in the docker configuration screen? I understand (assume) I will be able to mount a volume on a share backed by an encrypted drive.

     

    I can't figure out where the a docker's configuration is stored. If it is on the usb key itself then I guess it won't be protected.

     

    Same question for things like the Community Application plugins (specifically the rclone one).

     

     

  2. Hi all,

     

    I can see from searching that a number of times the question of securing either shares or the pool itself has come up, but I can't find any definitive answers on whether it is possible or how to achieve it. This is all about reducing the risk if a thief walks off with the disks.

     

    At the moment, should somebody walk off with my disks they have access to:

     - some private ssh keys

     - rclone config containing the keys for my encrypted offsite cloud backup

     - plex usernames (and passwords?)

     - backups of the various people that use my server as a target

     - and so on.

     

    I could solve each of those individually, by using VMs that encrypt the boot disk for example, but that means losing the [fantastic] benefit of the rclone plugins and dockers. At which point unRAID simply becomes a storage pool and disk health notifier (although it has my gmail one-time password in it!). I don't actually have any shares other than those used by the docker and VMs.

     

    My server is in the house so entering the crypt key on boot up is perfect for my needs.

     

    How do you all handle this?

  3. Hi, I searched, but couldn't find an answer to these questions:

    - are unRAID's SSH keys persisted across reboots and unRAID upgrades?

    - is unRAID's authorised_hosts persisted across reboots and unRAID upgrades?

     

    Essentially I use unRAID to rsync out to clients so I add unRAID's public key to the client's authorized-hosts. Likewise, I SSH into unRAID a far bit and copy my public key to unRAID's authorized-users and I want to ensure this will persist across reboots and upgrades.

     

    Any suggestions?

     

    Thanks!

×
×
  • Create New...