Vault use a master key divided in shares with the Shamir's secret sharing algorithm.
How should we divide the master key?
Vault use a master key divided in shares with the Shamir's secret sharing algorithm.
How should we divide the master key?
Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
Resolved | dereckson | T928 Deploy Vault to store credentials | |||
Wontfix | dereckson | T929 Determine a policy for vault master key |
The point is currently moot as we don't have an operations SIG large enough to allow key shares.
We can revisit the issue when the question is relevant again.