keyformat = raw | hex | passphrase
Controls what format the user's encryption key will be provided as. This property is only set when the dataset is encrypted.
Raw keys and hex keys must be 32 bytes long (regardless of the chosen encryption suite) and must be randomly generated. A raw key can be generated with the following command:
# dd if=/dev/urandom of=/path/to/output/key bs=32 count=1
Passphrases must be between 8 and 512 bytes long and will be processed through PBKDF2 before being used (see the pbkdf2iters property). Even though the encryption suite cannot be changed after dataset creation, the keyformat can be with zfs change-key
keylocation = prompt | file:// </absolute/file/path>
Controls where the user's encryption key will be loaded from by default for commands such as zfs load-key and zfs mount -l This property is only set for encrypted datasets which are encryption roots. If unspecified, the default is prompt.
Even though the encryption suite cannot be changed after dataset creation, the keylocation can be with either zfs set or zfs change-key If prompt is selected ZFS will ask for the key at the command prompt when it is required to access the encrypted data (see zfs load-key for details). This setting will also allow the key to be passed in via STDIN, but users should be careful not to place keys which should be kept secret on the command line. If a file URI is selected, the key will be loaded from the specified absolute file path.