Encrypt configuration files in the eCryptfs file system
Configuration files are encrypted in the eCryptfs file system when the system reboots or shuts down, and are decrypted when the system boots up and has to load the configuration to CMDB.
If the device supports TPM, the 32 byte eCryptfs encryption key is randomly generated and stored in the TPM, like the private-data-encryption key. If the device does not support TPM, the key is generated by the cryptographically secure pseudorandom number generator (CSPRNG) and stored on the disk. See Trusted platform module support and TPM support for FortiGate-VM for more information.