Uploaded image for project: 'Red Hat OpenStack Services on OpenShift'
  1. Red Hat OpenStack Services on OpenShift
  2. OSPRH-14359

Provide a mechanism for rotating pKEKs using SimpleCrypto

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Undefined Undefined
    • rhos-18.0.9
    • None
    • openstack-barbican
    • None
    • DFG Security: Test Sprint 2, DFG Security: Test Sprint 3
    • 2

      Goal: 

      • When using SimpleCrypto backend in Barbican, each Project is assigned a Project-specific Key-encryption Key (pKEK).  This pKEK is created automatically the first time a user with a role on that specific project submits a request to barbican do do cryptographic work.  This pKEK is used to encrypt all secrets owned by the project.
      • Currently there is no way to easily rotate these pKEKs 

      Acceptance Criteria:

      • A mechanism is provided to create a new pKEK for a specific project
      • A mechanism is provided to re-encrypt existing secrets using a specific (the latest) pKEK

              dmendiza Douglas Mendizabal
              dmendiza Douglas Mendizabal
              rhos-dfg-security
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: