https://www.freebsd.org/doc/handbook/swap-encrypting.html Article claims that the geli default AES keysize is 256 bits, is is in fact 128. The geli defaults are quite good already, and include a 4k sector size. More emphasis should be made on accepting the geli defaults as is.
Created attachment 161586 [details] Here's a patch for review...
A commit references this bug: Author: dru Date: Thu Oct 1 09:42:40 UTC 2015 New revision: 47461 URL: https://svnweb.freebsd.org/changeset/doc/47461 Log: Clarify GELI AES default keysize and that the defaults are probably fine. PR: 201979 Submitted by: Tom "Ludensen" Christensen Changes: head/en_US.ISO8859-1/books/handbook/disks/chapter.xml