Skip to content

Standardize List of allowed Barbican Plugins #509

Description

@josephineSei

Barbican is used to store secrets for encrypted resources in OpenStack. To store those secrets different plugins / backends can be used. For security issues, we should not allow all possible plugins.
E.g. there is the simply crypto plugin, that simply stores the Master KEK in the config file, and all other secrets in the database, which makes it easy to access all secrets.

Most likely testing this will be only possible through audits, as this is something configuration specific and/or deployment specific.

Definition of Done:

  • Proposal has been written with name of the form scs-xxxx-v1-slug.md (only substitute slug)
  • Proposal has the fields status, type, track set
  • Proposal has been voted upon in the corresponding team
  • Status has been changed into Draft, file renamed: xxxx replaced by document number
  • If applicable: test script has been written (this item may be moved into a separate issue so long as the state is Draft)

Metadata

Metadata

Assignees

Labels

IaaSIssues or pull requests relevant for Team1: IaaSSCS is standardizedSCS is standardizedSCS-VP10Related to tender lot SCS-VP10standardsIssues / ADR / pull requests relevant for standardization & certification

Type

No type

Projects

Status
Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions