[Not Accepted] Enable automated remote unlock of pools for the community edition (KMIP, TANG)

Problem / Justification:

It is a tedious process, if you have to enter the passphrase for locked pools upon boot on a daily basis. Passkeys are no option if you are worried for physical security of your TrueNAS server and want to save energy thus shutting down the TrueNAS server at nighttime.

Impact

This feature would improve the physical security of TrueNAS boxes of community edition users and also increase the user experience as a quality of life feature, as the pools unlock automatically, if certain conditions are met and the pools / shares are available directly.

User Story

(Please give a short description on how you envision some user taking advantage of this feature, what are the steps a user will follow to accomplish it)

A user has a second secured mini-pc (Futro, Dell Wyse, Pi) running 24/7, which offers a decryption service for the TrueNAS Server (PyKMIP, Clevis/Tang, Mando etc). The TrueNAS Server checks against this second pc, and if positive it decrypts its encypted pools automatically, users can then use their data without further action.

Thank you for submitting this feature request. After keeping it open to gauge community interest, we’re closing it as it hasn’t received enough votes to prioritize for development.

1 Like

It’s breaking my heart, but you do what you have to do :wink: