Subject: Re: seeking advice on encrypting file systems
To: VaX#n8 <vax@carolina.rr.com>
From: Stefan Schumacher <stefan@net-tex.de>
List: netbsd-users
Date: 02/05/2004 10:08:50
--WIyZ46R2i8wDzkSu
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

* VaX#n8 (vax@carolina.rr.com) wrote:
=20
> 1) CFS - a decade old, won't work with new rpcgen.  Can be coaxed into
> compilation, but requires several make commands with different args.
> It's all user-level.  The code is functional but definitely not elegant.
> Supports 3DES, but no modern ciphers.  Probably easier to re-write than
> to turn into a nice system.

cfs is available via pkgsrc, I used it with blowfish in 1.5.*
It's easy to configure  (http://www.net-tex.de/unix/cfs.html)
and even usable with NFS.

> 4) Others include rubberhose (no NetBSD support yet), StegFS (Linux only),
> encrypted loopback type devices (Linux and OpenBSD), BestCrypt (Linux).

There is cgd(4) available in current and someone backported it to
1.6.1, it's that wath you call loopback and it is very fast with AES.

I use cgd for /home and cfs for some special directories like
~/.gnupg and ~/mail

--=20
Lying, Dying, Screaming In Pain
Begging, Pleading, Bullets Drop Like Rain
Minds Explode, Pain Sheers To Your Brain
Radical Amputation This Is Insane  - SLAYER : Mandatory Suicide

--WIyZ46R2i8wDzkSu
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (NetBSD)

iD8DBQFAIfoSEfTEHrP7rjMRAiw/AJ9TPPwkouWJkEg2GNomKEDb6GTCngCgmGtg
HRagGkpujYD95z7rlvc7NPo=
=FCvb
-----END PGP SIGNATURE-----

--WIyZ46R2i8wDzkSu--