Jeff Abrahamson on 4 Feb 2006 15:38:44 -0000


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] /proc/crypto/cipher


On Sat, Feb 04, 2006 at 10:25:26AM -0500, Brian Epstein wrote:
>   [41 lines, 253 words, 1633 characters]  Top characters: etaionsr
> 
> On Sat, 4 Feb 2006, Jeff Abrahamson wrote:
> 
> > I remember reading somewhere that it should, in principle, be
> > possible to export such a file system with the encryption
> > happening on the client.  The doc I read said it would be
> > supported RSN, but that was a few years ago.  Has anyone gotten
> > that working here?
> >
> > That would be very nice for all manner of things if I could mount
> > something that is garbage on the server but meaningful on the
> > client.  In particular, it is one solution to remote backup to
> > untrusted servers.
> 
> I think I understand what you mean.  Basically, you have an
> untrusted network shared drive and you want to store files on it
> that the server admin can't get to, right?
> 
> If you are using samba or NFS, it is as straightforward as following
> the directions I posted.  All you have to do is save the initial
> image file on the remote server.

Right, of course.  Cool.

Of course, I couldn't run rsync (efficiently), but for things that
don't change alot (read: not most mbox files), I could write a small
db that keeps hashes of files so it can compare to the last backup and
copy to backup as needed.  Some background task could slowly do random
file integrity checks.


> For example, let's say that I have a samba mounted directory on my
> system.

Or sfs, in which case even the traffic to the server is encrypted!

-- 
 Jeff

 Jeff Abrahamson  <http://www.purple.com/jeff/>    +1 215/837-2287
 GPG fingerprint: 1A1A BA95 D082 A558 A276  63C6 16BF 8C4C 0D1D AE4B

Attachment: signature.asc
Description: Digital signature

___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug