<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>ISCSI on nagg.eu</title><link>https://nagg.eu/tags/iscsi/</link><description>Recent content in ISCSI on nagg.eu</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sat, 26 Dec 2020 00:00:00 +0000</lastBuildDate><atom:link href="https://nagg.eu/tags/iscsi/index.xml" rel="self" type="application/rss+xml"/><item><title>LUKS encrypted TGT ISCSI target and initiator</title><link>https://nagg.eu/luks-encrypted-tgt-iscsi-target-and-initiator/</link><pubDate>Sat, 26 Dec 2020 00:00:00 +0000</pubDate><guid>https://nagg.eu/luks-encrypted-tgt-iscsi-target-and-initiator/</guid><description>&lt;p&gt;After the CentOS fiasco (good job Redhat/IBM) and since we are more or less in
lockdown I decided to invest a couple of days to migrate my home infra from
CentOS 7 to Debian 10.&lt;br&gt;
One of my physical machines, which was also CentOS 7 based, is used as ISCSI
target.&lt;/p&gt;
&lt;h2 id="debian-10---server-aka-target"&gt;Debian 10 - Server A.K.A. Target&lt;/h2&gt;
&lt;p&gt;Install the required packages:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;$ sudo apt-get install tgt dkms 
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Create a device backstore:&lt;/p&gt;</description></item><item><title>Remote encrypted backup with iSCSI and LUKS2</title><link>https://nagg.eu/remote-encrypted-backup-with-iscsi-and-luks2/</link><pubDate>Mon, 27 Aug 2018 19:19:08 +0000</pubDate><guid>https://nagg.eu/remote-encrypted-backup-with-iscsi-and-luks2/</guid><description>&lt;p&gt;The idea here is to have a LUKS2 encrypted volume stored on a remote server
that allows authenticated clients to load and decrypt the data without letting
the server know what is being written, read and stored.&lt;br&gt;
Keep in mind that this solution is not 100% bulletproof, you still kind of have
to trust the backup server because a malicious entity might take multiple
snapshots of the encrypted iSCSI LUN and try to crack the encryption.&lt;/p&gt;</description></item></channel></rss>