Settings

Theme

Has anybody seen my keys? A key-hierarchy strategy for rack-level security

rfd.shared.oxide.computer

35 points by cyb0rg0 · 4 comments

Reader

3 threads
crabmusket

Oxide's trust quorum approach is also discussed on this podcast episode:

https://oxide-and-friends.transistor.fm/episodes/building-a-...

benmmurphy

Is there any concern in this scheme with losing access to storage either temporarily or permanently due to losing access to key shares?

orielhaim

The bit I liked most is wrapping the old rack secret under a key derived from the new epoch so prepare can hand out shares without unlocking until commit

That tension between needing both secrets for ZFS rekey and only serving shares for the committed epoch is a real distributed systems headache and this is a clean way out of it

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection