How to recover the zpool encryption key after OS disk failure

Is the device plugged in?

i plugged the old os usb back in after it booted up. it won’t boot up with is plugged in no matter which drive i select. I suspect this is because of the VM that started this mess

The old boot drive needs to be plugged in and detected.

zpool import

zpool status
no pools available to import
  pool: boot-pool
 state: ONLINE
config:

        NAME        STATE     READ WRITE CKSUM
        boot-pool   ONLINE       0     0     0
          mirror-0  ONLINE       0     0     0
            sdc3    ONLINE       0     0     0
            sdf3    ONLINE       0     0     0

errors: No known data errors

  pool: oldboot
 state: ONLINE
  scan: scrub repaired 0B in 00:00:10 with 0 errors on Sat Jul 19 03:45:11 2025
config:

        NAME        STATE     READ WRITE CKSUM
        oldboot     ONLINE       0     0     0
          sdg3      ONLINE       0     0     0

errors: No known data errors

  pool: zpool
 state: DEGRADED
status: One or more devices could not be used because the label is missing or
        invalid.  Sufficient replicas exist for the pool to continue
        functioning in a degraded state.
action: Replace the device using 'zpool replace'.
   see: https://openzfs.github.io/openzfs-docs/msg/ZFS-8000-4J
config:

        NAME                                      STATE     READ WRITE CKSUM
        zpool                                     DEGRADED     0     0     0
          raidz2-0                                DEGRADED     0     0     0
            3819f55e-fcb6-4a78-8cac-6c56cd5b2680  ONLINE       0     0     0
            7ef6f78c-5a38-4dc9-99da-6243677b79f7  ONLINE       0     0     0
            ab235bf6-08e7-47e4-b70f-008689e5515f  ONLINE       0     0     0
            1fdc764f-5d69-4899-b1ea-90cbde3f7918  ONLINE       0     0     0
            18075899723185650379                  UNAVAIL      0     0     0  was /dev/disk/by-partuuid/4ed67b79-02cf-47fb-854b-b820f6f62d98

errors: No known data errors

Export the oldboot pool:

zpool export oldboot

Then start from these steps in this order.

truenas_admin@truenas[~]$ sudo zpool export oldboot
truenas_admin@truenas[~]$ sudo mkdir /mnt/recovery
mkdir: cannot create directory ‘/mnt/recovery’: File exists
truenas_admin@truenas[~]$ cd /mnt/recovery
truenas_admin@truenas[/mnt/recovery]$ zpool import -f -o readonly=on -R /mnt/oldboot -d /dev/sdg3 -N 2650431139805676226 oldboot
zsh: command not found: zpool
truenas_admin@truenas[/mnt/recovery]$ sudo zpool import -f -o readonly=on -R /mnt/oldboot -d /dev/sdg3 -N 2650431139805676226 oldboot
truenas_admin@truenas[/mnt/recovery]$ sudo mount -t zfs -o ro oldboot/ROOT/25.04.1/data /mnt/oldboot/data
filesystem 'oldboot/ROOT/25.04.1/data' cannot be mounted using 'mount'.
Use 'zfs set mountpoint=legacy' or 'zfs mount oldboot/ROOT/25.04.1/data'.
See zfs(8) for more information.

Before you try the zfs mount method, make sure that the mountpoint will not collide with anything.

zfs get mountpoint oldboot/ROOT/25.04.1/data
truenas_admin@truenas[/mnt/recovery]$ sudo zfs get mountpoint oldboot/ROOT/25.04.1/data
NAME                       PROPERTY    VALUE              SOURCE
oldboot/ROOT/25.04.1/data  mountpoint  /mnt/oldboot/data  local

It’s safe to do this then:

zfs mount oldboot/ROOT/25.04.1/data

done

Check the contents:

ls -l /mnt/oldboot/data
truenas_admin@truenas[/mnt/recovery]$ ls -l /mnt/oldboot/data
total 149
-rw------- 1 root root    424 Jun  1 11:22 dhparam.pem
-rw------- 1 root root 851968 May 26 07:29 factory-v1.db
-rw------- 1 root root 819200 Jul 25 09:24 freenas-v1.db
-rw------- 1 root root    108 May 26 07:39 manifest.json
-rw------- 1 root root     32 Jun  1 11:21 pwenc_secret
drwx------ 2 root root      2 Jun  1 11:17 sentinels
drwxr-xr-x 3 root root      3 Jun  1 11:17 subsystems
-rw------- 1 root root      0 Jun  1 11:17 truenas-eula-pending
-rw------- 1 root root    239 Jul 25 09:16 user-services.json
drwx------ 2 root root      3 Jun  1 11:21 zfs

Copy the needed files into your current directory:

cp -v /mnt/oldboot/data/{freenas-v1.db,pwenc_secret} ./
truenas_admin@truenas[/mnt/recovery]$ sudo cp -v /mnt/oldboot/data/{freenas-v1.db,pwenc_secret} ./
'/mnt/oldboot/data/freenas-v1.db' -> './freenas-v1.db'
'/mnt/oldboot/data/pwenc_secret' -> './pwenc_secret'

this is looking promising

I made a modification to the original code so that you can run it directly on TrueNAS, outside of the old boot environment.

wget "https://pastebin.com/raw/uGWGw6Tp" -O decode.py

You can check the code, since you should never trust any scripts or code online. Up to you.

The next step is easy when you’re ready.

i used cat to view the code and am comfortable with it. how do i run it?

Don’t paste the results in here:

python3 decode.py

It should hopefully decrypt and print a long hexstring.

It will look something like this: f69bb6091a43107dbb25ec59486eb035eeed3f6e89325aa15ec52135774e356a

This is your root dataset’s encryption keystring. Copy and paste it to manually unlock your root dataset of the pool.

Hopefully it’s the latest keystring and it works.

the script is having a hard time opening the db file. What line am I trying to edit.

Don’t edit any lines. It’s probably a permissions issue.

While still inside the path /mnt/recovery:

sudo chmod 777 *