Re: How to salvage a degraded mdadm RAID1 with as little data loss as possible?
| Newsgroups | gmane.linux.debian.user |
|---|---|
| Message-ID | <[email protected]> |
On Tue, Jun 23, 2026 at 10:33:01AM -0700, David Christensen wrote: [...] > Both configurations work, but have different performance and security > considerations: > > * partitions > RAID > encryption > filesystem > > Will encrypt the RAID virtual block device, saving CPU cycles and > requiring one passphrase and/or key. > > * partitions > encryption > RAID > filesystem > > Will encrypt each partition, arguably improving security but requiring > more CPU cycles and passphrases/ keys. Actually it would reduce security, IMO, because the opponent would have to find just one of both keys (the content is mirrored), thus potentially reducing the key strength by one bit. Not a big deal, granted :) Cheers -- tomás
signature.asc
(application/pgp-signature, 195 B)
-----BEGIN PGP SIGNATURE----- iF0EABECAB0WIQRp53liolZD6iXhAoIFyCz1etHaRgUCajrMIQAKCRAFyCz1etHa Rli5AJ95jP6mQt+4UZrM55GyurLiClOvqQCeLnt/nhegl2GSS888aFpScbXNWxQ= =dNIt -----END PGP SIGNATURE-----