[MXS-2662] KMIP Binlog Data At Rest Encryption Created: 2019-09-05  Updated: 2022-07-19  Resolved: 2022-07-19

Status: Closed
Project: MariaDB MaxScale
Component/s: binlogrouter
Affects Version/s: None
Fix Version/s: 22.08.0

Type: New Feature Priority: Major
Reporter: Todd Stoffel (Inactive) Assignee: markus makela
Resolution: Fixed Votes: 0
Labels: None

Sub-Tasks:
Key
Summary
Type
Status
Assignee
MXS-4129 Add encryption to binlogrouter Sub-Task Closed markus makela  
MXS-4130 Create a generic encryption facility Sub-Task Closed markus makela  
MXS-4131 Create a generic key management facility Sub-Task Closed markus makela  
MXS-4157 Document encryption key management in... Sub-Task Closed markus makela  
MXS-4158 Test pinloki encryption Sub-Task Closed markus makela  
Epic Link: Pinloki Project
Sprint: MXS-SPRINT-157, MXS-SPRINT-158, MXS-SPRINT-159, MXS-SPRINT-160, MXS-SPRINT-161, MXS-SPRINT-162

 Description   
  • Add data-at-rest encryption to the binlogrouter
  • Make it possible to use KMIP to retrieve encryption keys
  • Add support (or at least make it easy to do in the future) for other key management systems (e.g. Hashicorp Vault)


 Comments   
Comment by markus makela [ 2022-05-09 ]

Could use https://github.com/OpenKMIP/libkmip for the client library and PyKMIP for testing it.

Generated at Thu Feb 08 04:15:46 UTC 2024 using Jira 8.20.16#820016-sha1:9d11dbea5f4be3d4cc21f03a88dd11d8c8687422.