Barbican is used to store secrets for encrypted resources in OpenStack. To store those secrets different plugins / backends can be used. For security issues, we should not allow all possible plugins.
E.g. there is the simply crypto plugin, that simply stores the Master KEK in the config file, and all other secrets in the database, which makes it easy to access all secrets.
Most likely testing this will be only possible through audits, as this is something configuration specific and/or deployment specific.
Definition of Done:
Barbican is used to store secrets for encrypted resources in OpenStack. To store those secrets different plugins / backends can be used. For security issues, we should not allow all possible plugins.
E.g. there is the simply crypto plugin, that simply stores the Master KEK in the config file, and all other secrets in the database, which makes it easy to access all secrets.
Most likely testing this will be only possible through audits, as this is something configuration specific and/or deployment specific.
Definition of Done:
scs-xxxx-v1-slug.md(only substituteslug)status,type,tracksetDraft, file renamed:xxxxreplaced by document numberDraft)