TrueNAS
Products
Support & Resources
Solutions
Company
Sign In
TrueNASTrueNAS Development Documentation
This content follows experimental development changes in TrueNAS 28, a future version of TrueNAS.
Use the Product and Version selectors above to view content specific to a stable software release.

Encryption Screen

The Datasets screen shows the Encryption card after selecting a datasets, root, non-root parent, and child, or zvols with encryption.

Dataset Tree Table Encryption Icons
Figure 1: Dataset Tree Table Encryption Icons

The Datasets tree table includes lock icons and descriptions that indicate the encryption state of datasets.

IconStateDescription
DatasetLockedEncryptionIconLockedDisplays for locked encrypted root, non-root parent and child datasets.
DatasetUnlockedEncryptionIconUnlockedDisplays for unlocked encrypted root, non-root parent and child datasets.
DatasetLockedByAncestorEncryptionIconLocked by ancestorDisplays for locked datasets that inherit encryption properties from the parent.
DatasetUnlockedbyAncestorEncryptIconUnlocked by ancestorDisplays for unlocked datasets that inherit encryption properties from the parent.

Edit on the Encryption card opens the Edit Encryption Options for dataset namne window.

Lock or Unlck conditionally show on the Encryption card. Key-encrypted datasets or zvols cannot be locked or unlocked.

Export Key options shows on the Encryption card. when the selected dataset is key-encypted.

Edit Encryption Options Window

The Edit Encryption Options for dataset name window shows the same encryption settings found on the Add Dataset > Advanced Options screen. It allows changing the type of encryption applied to the dataset, changing the encryption key or passphrase. The type of encryption and the options are set for a dataset when it is created or are inherited from the root dataset.

Encryption Options Passphrase Type Window
Figure 2: Encryption Options Passphrase Type Window
Encryption Options Key Type Window
Figure 3: Encryption Options Key Type Window
Encryption Settings

SettingDescription
Encryption TypeSets the type of encryptiuon applied to the dataset as Key or Passphrase. Key shows key-based encryption settings, a system-generated key field, an option to use a manual entry key, and a key-based encryption algorithms. Passphrase shows text fields for manual or copy/paste entry of a passphrase, and passphrase authentication algorithms. It is disabled for child datasets of encrypted parent datasts.
Generate keySets TrueNAS to generate a random encryption key for securing the dataset. Shows when Encryption Type is set to Key. Clearing this shows the Key field that accepts manual or copy/paste entry of an encryption key.
Warning! The encryption key is the only means to decrypt the information stored in a key-encrypted dataset. Store encryption keys in a secure location! Creating a new key file invalidates a previously downloaded key file (for this dataset). Delete any previous key file backups and back up the new key file.
KeySpecifies a manually entered encryption key string to secure the dataset.
AlgorithmSets the encryption algorithm. Shows a list of mathematical instruction algorithms that determine how plaintext converts into ciphertext for key and passphrase encryption types. See Advanced Encryption Standard (AES) for more details on each option.
Passphrase
Confirm Passphrase
Specifies an alphanumeric string or phrase to secure the dataset.
pbkdf2itersSets the number of password-based key deviation function 2 (PBKDF2) iterations used for reducing vulnerability to brute-force attacks. Entering a number larger than 100000 is required. See PBKDF2 for more details.

The Edit Encryption Options for dataset name window for encrypted child datasts or zvols shows only the Inherit encryption properties from the parent and Confirm options.

Edit Encryption Options - Encrypted Child Datasets
Figure 4: Edit Encryption Options - Encrypted Child Datasets

Inherit encryption properties from parent shows on the Edit Encryption Options for dataset name window when the dataset or zvol is a child of an encrypted parent dataset. It allows changing the encryption authentication key or passphrase for the child datasets or zvol, but you cannot change the type of encryption applied. Disabling it shows the current encryption type and settings for the parent dataset. Leaving it enabled retains the encrytpion settings of the parent.

Encryption Options Passphrase Type Window
Figure 5: Encryption Options Passphrase Type Window

Confirm is required and activates the Save button.

For more information on dataset encryption, see the Encrypting Datasets.

Export Key Options

The Encryption card for root datasets (pools) with encryption includes the Export All Keys and Export Key options, but it does not include the Lock option.

If a dataset is encrypted using a key, the Encryption card for that dataset includes the Export Key option.

All child datasets or zvols inherit the encryption of the parent dataset.

Export All Keys Dialog

Export All Keys opens a confirmation dialog with the Download Keys option that exports a JSON file of all encryption keys to the system download folder.

Export All Keys
Figure 6: Export All Keys

Export Key Dialog

Export Key opens a dialog showing the key for the selected dataset and the Download Key button. Download Key exports the key to a JSON file and saves it in your system download folder.

Export Key
Figure 7: Export Key

The Lock button does not show for key-encrypted datasets.

Lock Dataset Dialog

Lock shows on the Encryption card for passphrase-encrypted datasets. It does not show for an encrypted child that inherits encryption from an encrypted parent when the lock state is controlled by the parent dataset for that child dataset. The locked icon for child datasets that inherit encryption is the locked-by-ancestor icon.

Lock opens the Lock Dataset confirmation dialog with the option to Force unmount and Lock the dataset.

Lock Dataset Dialog
Figure 8: Lock Dataset Dialog

Force unmount disconnects any client system accessing the dataset via the sharing protocol. Do not select this option unless you are certain the dataset is not used or accessed by a share, application, or other system services.

After locking a dataset, the Encryption screen shows Locked as the Current State and adds the Unlock option.

Unlock Datasets Screen

Unlock on the Encryption card shows for locked datasets that are not child datasets that inherit encryption from the parent dataset. Unlock opens the Unlock Datasets screen.

Unlock Datasets Screen
Figure 9: Unlock Datasets Screen
Unlock Dataset Settings
SettingDescription
DatasetShows the path to the selected encrypted dataset.
Dataset PassphraseSpecifies the user-defined passphrase string entered when you created and encrypted the dataset.
ForceAdds a force flag to the unlock operation. In some cases, the provided passphrase might be valid, but the path where the dataset is supposed to be mounted after being unlocked already exists and is not empty. In this case, the unlock operation fails. Adding the force flag can override this, and when selected, the system renames the existing dataset mount directory/file path and unlocks the dataset.

Unlocking encrypted datasets shows two additional dialogs: Unlock Datasets and Unlocked Datasets.

Unlock Datasets Dialog
Figure 10: Unlock Datasets Dialog

Continue on the Unlock Datasets dialog starts the unlocking process, fetches data and opens the Unlock Datasets dialog.

Unlocked Datasets Dialog
Figure 11: Unlocked Datasets Dialog

When the locked dataset has child datasets, both are unlocked at the same time and show on the Unlocked Datasets dialog.

The Unlocked Datasets dialog opens after clicking Continue on the Unlock Datasets dialog and shows the status of unlocked datasets and the mount path to the datasets.

Pool Encryption Screens

The Encryption options on the Pool Creation Wizard > General screen set encryption for the entire pool, and when equipped with SEDs, can set the global SED encryption password.

Encrypting the root dataset (pool-level encryption) creates a single point of failure. Losing one key makes the entire pool inaccessible.

Best practice Do not enable encryption during pool creation. Instead, create an unencrypted pool with individually encrypted datasets and zvols. This allows independent key management, selective unlock, isolated failures, and simplified recovery.

The Download Encryption Key warning window opens after saving a new pool as part of the pool creatiing process. It downloads a JSON file to your system.

Download Pool Encryption Key
Figure 12: Download Pool Encryption Key