惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Securelist
腾讯CDC
L
LangChain Blog
aimingoo的专栏
aimingoo的专栏
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园_首页
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
云风的 BLOG
云风的 BLOG
P
Proofpoint News Feed
罗磊的独立博客
爱范儿
爱范儿
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
H
Help Net Security
Vercel News
Vercel News
MyScale Blog
MyScale Blog
博客园 - 叶小钗
The Register - Security
The Register - Security
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
量子位
Y
Y Combinator Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
NISL@THU
NISL@THU
GbyAI
GbyAI
SecWiki News
SecWiki News
M
MIT News - Artificial intelligence
Engineering at Meta
Engineering at Meta
P
Privacy International News Feed
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
C
Check Point Blog
博客园 - 聂微东
Project Zero
Project Zero
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Latest news
Latest news
V
Vulnerabilities – Threatpost
T
The Blog of Author Tim Ferriss
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
D
Darknet – Hacking Tools, Hacker News & Cyber Security
T
Tor Project blog
F
Fortinet All Blogs
Recorded Future
Recorded Future
IT之家
IT之家
D
Docker
The GitHub Blog
The GitHub Blog
V
Visual Studio Blog
MongoDB | Blog
MongoDB | Blog
T
Threat Research - Cisco Blogs
Hugging Face - Blog
Hugging Face - Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
V
V2EX

TrueNAS – Open Enterprise Storage

What We Heard at NAB 2026 | TrueNAS - Open Enterprise Storage TrueNAS V160 Launched: High Performance, No All-Flash Tax TrueNAS 26 Is Here: What's New in This Major Release TrueNAS Connect: Enterprise Features on Your Own Hardware TrueNAS Immutability: Multi-Layered Data Protection & Ransomware Defense TrueNAS CEO Note to Community: We Are All TrueNAS TrueNAS 25.10.2 Goldeye: 100+ Fixes & What's New TrueNAS Names Brett Davis CEO for Enterprise Growth TrueNAS Plans for 2026: TrueNAS 26 & OpenZFS 2.4 Roadmap TrueNAS Connect Plus Now Available for All Community Users TrueNAS R60: High-Speed NVMe Storage for AI Workloads Introducing TrueNAS WebShare: Secure Web-Based File Sharing TrueNAS 25.10.1: Goldeye Matures, Performs, and Connects TrueNAS & Veeam v13: Turnkey Cyber‑Resilient Backups Customer Advantages of the TrueNAS Open Core Model TrueNAS Named Data Storage Company of the Year 2025 TrueNAS 25.10: Smarter, Streamlined Updates & Tools TrueNAS F-Series Shines at IBC with Two “Best of Show” Awards TrueNAS 25.10 “Goldeye”: NVMe‑oF, Unified, Simplified Storage Introducing TrueNAS Connect: Secure Monitoring & Alerts The ESG Advantage of Open Enterprise Architecture: Why TrueNAS Is the Sustainable Choice | TrueNAS - Open TrueNAS 25.10-RC1: New Features, Fixes & OpenZFS 2.3.4 Seamless Setup: Exploring TrueNAS Web-Driven Installation | TrueNAS - Open Enterprise Storage TrueNAS 25.10 “Goldeye” BETA is Available TrueNAS 25.10 “Goldeye” Highlights TrueNAS 25.04.2: Fangtooth restores Virtualization iXsystems Rebrands as TrueNAS to Reflect Market Momentum in Enterprise Storage | TrueNAS - Open Enterprise June 1 - Apps Migration Deadline for TrueNAS 24.04 and 23.10 TrueNAS 25.04.1: Fangtooth Unification Gains Momentum TrueNAS 24.10.2.2 Prepares for IP Addressing of Apps TrueNAS H30 and F100 add Fast Dedup with TrueNAS 25.04 Meet TrueNAS Community Edition – The Future of Open Storage TrueNAS Apps Made Easy with Electric Eel & Fangtooth TrueNAS H30 Secures Two ‘Best of Show’ Honors at NAB 2025 | TrueNAS - Open Enterprise Storage TrueNAS H30 Wins Best of Show Awards at NAB 2025 TrueNAS 25.04: Fangtooth is RELEASED Slash Your Virtualization Costs with TrueNAS Storage TrueCommand 3.1 Enhances Management and Monitoring TrueNAS 25.04: Fangtooth Unification Begins with New Features Fangtooth Unification Begins | TrueNAS iXsystems Experiences Record Growth in TrueNAS Enterprise Storage, Spins Off Server Business to Amaara How to Set Up and Install TrueNAS CORE Yes, You Can (Still) Virtualize TrueNAS TrueNAS enables Container Storage and Kubernetes | TrueNAS - Open Enterprise Storage TrueNAS 12.0-U2 is Released | TrueNAS - Open Enterprise Storage OpenZFS 2.0 Ships First on TrueNAS | TrueNAS - Open Enterprise Storage TrueNAS 12.0-U1 is Scheduled for early December | TrueNAS - Open Enterprise Storage iXsystems TrueNAS M60 Recognized as SDC Awards Storage Hardware Innovation of the Year Finalist | TrueNAS - TrueNAS 12.0 is Released! The TrueNAS Mini X and Mini X+ are here! Cross-Site Disaster Recovery with TrueNAS TrueNAS SCALE Release Plan | TrueNAS - Open Enterprise Storage iXsystems Unveils Industry's Fastest OpenZFS Storage System with Launch of TrueNAS M60 | TrueNAS - Open TrueNAS 12.0 BETA2 Showcases Performance Improvements | TrueNAS - Open Enterprise Storage Be One of the First to Test Drive TrueNAS 12.0 BETA | TrueNAS - Open Enterprise Storage TrueNAS is Multi-OS New-New TrueNAS Logo Unveiled | TrueNAS - Open Enterprise Storage Recession Proof Storage | FreeNAS 11.3-U3.1 Now Available - Issue #80 | TrueNAS - Open Enterprise Storage Open Source Infrastructure is Recession-Proof | TrueNAS - Open Enterprise Storage Understanding How OpenZFS Keeps Your Data Safe | TrueNAS - Open Enterprise Storage You Can Influence the TrueNAS CORE Roadmap! | TrueNAS - Open Enterprise Storage TrueNAS CORE is the new FreeNAS Setting Up Users, Permissions, and ACLs on FreeNAS | TrueNAS - Open Enterprise Storage TrueNAS Updates for VMware vSphere 7 | TrueNAS - Open Enterprise Storage How to Set Up Windows SMB Shares on FreeNAS | TrueNAS - Open Enterprise Storage FreeNAS and TrueNAS are Unifying Introducing the FreeNAS Mini E+ and All-Flash Minis | TrueNAS - Open Enterprise Storage Plex Permissions in FreeNAS 11.3 | TrueNAS - Open Enterprise Storage Latest TrueNAS and FreeNAS Release Delivers Wizards, Plugins, and Accelerated Replication | TrueNAS - Open How To Back Up Google Drive to FreeNAS | TrueNAS How To Enable Wireguard on FreeNAS 11.3 | TrueNAS - Open Enterprise Storage The Official FreeNAS Hardware Guide | TrueNAS - Open Enterprise Storage December 11 Plugins Update: ClamAV Fix & CloudStack FreeNAS Mini Black Friday Sale Starts Now! - Issue #73 | TrueNAS - Open Enterprise Storage Breaking Down the FreeNAS Mini E! | TrueNAS TrueCommand Shifts to Prime Time | TrueNAS - Open Enterprise Storage AMD EPYC 7002 Powers Scalable TrueNAS Solutions FreeNAS and TrueNAS 11.3 make their Debuts October 30 Plugins Update | TrueNAS - Open Enterprise Storage Overview of Datasets and Snapshots in FreeNAS | TrueNAS - Open Enterprise Storage September 13 Plugins Update | TrueNAS - Open Enterprise Storage Mount a TrueNAS or FreeNAS Share to a Docker Host | TrueNAS - Open Enterprise Storage Open ZFS vs. Btrfs | and other file systems | TrueNAS - Open Enterprise Storage ZFS vs. OpenZFS Backup Evolved: Asigra Plugin for FreeNAS Back Up Plugins and Jails on FreeNAS | TrueNAS Take Command of Your NAS Fleet with TrueCommand™ | TrueNAS - Open Enterprise Storage Run S3 Object Storage on FreeNAS and TrueNAS | TrueNAS - Open Enterprise Storage Sync Files to Dropbox with TrueNAS or FreeNAS February Plugin Updates & New Plugins for Testing Six Metrics for Measuring ZFS Pool Performance Part 2 | TrueNAS - Open Enterprise Storage Six Metrics for Measuring ZFS Pool Performance Part 1 | TrueNAS - Open Enterprise Storage TrueNAS M-Series Certified for Veeam Backup FreeNAS 11.1 is Now Available for Download! | TrueNAS FreeNAS 11.0 Released with VM & S3 Storage Support To SLOG or not to SLOG: How to best configure your ZFS Intent Log | TrueNAS - Open Enterprise Storage vCenter Web Client Plug-in for TrueNAS Now Available | TrueNAS - Open Enterprise Storage The ZFS ZIL and SLOG Demystified | TrueNAS - Open Enterprise Storage FreeNAS: A Worst Practices Guide | TrueNAS - Open Enterprise Storage FreeNAS vs TrueNAS
Immutable Backup & Enterprise Storage Security Features | TrueNAS 2024
Pee Jay Latombo · 2024-09-13 · via TrueNAS – Open Enterprise Storage

Network security is the first line of defense against data breaches. TrueNAS, when configured within a secure network, offers enhanced protection against security risks.

This blog explores the security features in TrueNAS SCALE, including the new features in Electric Eel (24.10), as well as the TrueSecure™ package, designed to meet stringent commercial and government security standards.

TrueSecureTM is an optional feature package for TrueNAS Enterprise that offers a robust set of enterprise-level software and hardware capabilities to meet high security and compliance standards.

The key features of TrueSecureTM include:

    • FIPS 140-validated cryptographic modules for SSL-based encryption of data in transit
    • FIPS 140-validated HDD and SSD media for encryption of data at rest
    • KMIP for centralized management of encryption keys
    • Optional restricted administration roles for limited access
    • Immutable ZFS Snapshots to further enhance ransomware protection
    • General Purpose OS STIG support and NIST 800-209 compliance to meet US federal requirements

With the optional TrueSecureTM feature package, TrueNAS complies with the requirements of the NIST Cybersecurity Framework to make Federal-level storage security as cost-effective as possible. With this foundation, TrueNAS can be used for federal government use cases from military bases to law enforcement and secure research organizations.

By default, TrueNAS includes a wide range of capabilities intended to simplify the delivery of secure storage infrastructure, including network encryption, access control, auditing, and logging functions.

Security notices (CVEs) and the Software Bill of Materials (SBoM) are available via the updated TrueNAS security site. For developers or those with an intimate knowledge of programming, the TrueNAS source code is available for review via GitHub. We believe that sunlight is one of the best disinfectants.

TrueNAS Security Features

Secure for Enterprises

While some consumer storage vendors prioritize ease of use over security, exposing themselves to exploits that lead to virus or ransomware attacks, TrueNAS places security at the forefront. With built-in features that reduce attack vectors and restrict admin access, TrueNAS is designed to seamlessly integrate into secure network environments, providing enterprise protection against evolving threats.

New threats come online with such frequency that new features and tools are always needed to stay ahead of the curve. In the last year, TrueNAS Enterprise has added a FIPS 140-2 validated crypto module and the option to enable Restricted Admins on Enterprise appliances. Let’s dive into Restricted Admins and then review the other key security features available in Electric Eel.

Restricted Admins

TrueNAS Enterprise 24.04 and later versions introduce three admin roles—System Admins, Storage Admins, and Monitor-Only Admins—to enhance security and limit access. This multi-level admin structure ensures that sensitive actions are restricted to authorized personnel, significantly reducing the risk of unauthorized data access or manipulation.

System Admins have the authority to set up the system, much like the original root user.  They set up the system and its security posture, including connections to AD, LDAP, and KMIP and configuring any passwords required.  However, once the system is set up, they then create storage admins to operate the system. They are needed to retire systems and delete pools or immutable snapshots. For security reasons, only a select few users should be made System Admins.

Storage Admins have the authority to create, configure, and delete shares and snapshots, and can also set immutability; however, they do not have the authority to destroy pools or immutable snapshots. There can be as many Storage Admins as needed.

Monitor-Only Admins have the authority to review configurations, performance, and check alerts, but can’t make changes to the system. They are often the storage users in the organization who can check that systems are supporting their applications. Where needed, they can request that a Storage Admin sign in to make approved changes.

Administrator roles are restricted regardless of the method of access, whether that be the WebUI, CLI, or API, with optional Two-Factor Authentication (2FA) used to secure interactive access.

Restricted-Admins

TrueNAS Security Features

TrueNAS offers a comprehensive suite of security features, including encryption, access control, and logging, all designed to protect data integrity and compliance. These features ensure that TrueNAS remains a secure and reliable choice for organizations of any size.

TrueNAS Security Features

While TrueNAS provides robust security, it’s essential to also follow general network security best practices, such as using firewalls, Intrusion Detection/Prevention Systems, and integrating with a directory service such as Active Directory or LDAP, to maximize your defense-in-depth..

With recent releases of TrueNAS SCALE, there have been many security advancements:

Rootless administration allows changing away from using the commonly known “root” username, and instead setting up your own unique administrator usernames and passwords.  This is the precursor to Restricted Admins.

Snapshot retention tags can prevent snapshots from being deleted, remaining on the system permanently as a restore point. This provides additional protection against ransomware by allowing the administrator to make a decision on when it is safe and appropriate to remove the ZFS snapshot outside of normal retention policies. Immutability is managed via this mechanism and ensured through Restricted Admins.

2-Factor Authentication (2FA) verifies the identities of administrators using Google Authenticator or any Time-based One-Time Password (TOTP) compliant authentication application.

iX-Storj Globally Distributed Storage inherently protects data by encrypting it on the TrueNAS system before distributing the data via erasure coding over a global network. Thanks to the combination of zero-trust and zero-knowledge encryption in use, no storage provider or government entity has access to your private data stored on iX-Storj. Electric Eel adds a cloud backup capability that provides robust backup and restore capabilities with immutable cloud snapshots for both shares and LUNs.

Auditing and logging capabilities have been added to increase security of system administration and SMB file sharing.  Electric Eel adds logging of all configuration changes, any sudo commands, and attempts to login via ssh or Web UI.

Authentication and Authorization capabilities are required in any organization. Active Directory and LDAP are used to provide identity authentication and user authorization services for a whole organization. TrueNAS integrates well into these services. With Electric Eel, FreeIPA is also supported for those looking for an Open Source identity management.

TrueSecure Features

Some security capabilities are specific to the TrueSecure feature package available with TrueNAS Enterprise. As a reminder, TrueSecure provides the following additional security capabilities:

Restricted Admins provide separate roles for system/security admins, storage admins and monitors. As described earlier, these role separations are critical for larger organizations.

FIPS 140-2 validated storage media provide highly secure Data-at-Rest capabilities. Both HDD and SSD (SAS or NVMe) drives can be provided on standard TrueNAS Enterprise systems. These drives are similar to self-encrypting drives (SED) but include tamper-proof mechanisms for additional security.

FIPS 140-2 validated software encryption module provides highly secure Data-in-Transit capabilities. The validated encryption algorithms are more secure than the current open source algorithms and validated for use in critical Federal use-cases. For example, these algorithms will protect administration and data replication tasks.

Key Management Interoperability Protocol (KMIP) provides the capability to centralize the management of SED and ZFS encryption passwords for larger organizations. This capability is also in TrueNAS Enterprise 13.0.

Security Technical Information Guides (STIGs) for use with TrueSecure to help lockdown TrueNAS Enterprise systems and ensure secure operation. A General Purpose OS STIG is available for guidance.

TrueNAS Enterprise is secure storage that can be configured for government-grade security. Together, all of these features can be used with Active Directory to comply with the requirements identified in NIST 800-209, the USA cyber security standard for storage systems. Similarly, these features address the security requirements identified for storage systems in ISO/IEC 27040.

With the upcoming Electric Eel release in fall 2024, new features and tools will continue to enhance security. If you’d like to learn about any TrueNAS Enterprise system or security needs, please feel free to contact us.

Discuss this article in the TrueNAS Forums!