Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enable forced credential rotation in secrets-config utility [ossf silver] #4227

Open
bnevis-i opened this issue Nov 7, 2022 · 0 comments
Open
Labels
enhancement New feature or request

Comments

@bnevis-i
Copy link
Collaborator

bnevis-i commented Nov 7, 2022

🚀 Feature Request

Relevant Package [REQUIRED]

secrets-config utility

Description [REQUIRED]

From OpenSSL silver badge requirements:
The project MUST support storing authentication credentials (such as passwords and dynamic tokens) and private cryptographic keys in files that are separate from other information (such as configuration files, databases, and logs), and permit users to update and replace them without code recompilation. If the project never processes authentication credentials and private cryptographic keys, select "not applicable" (N/A)

We are compliant with this requirement with the exception that we have no supported mechanism to force a credential rotation.

Describe the solution you'd like

Enhance the secrets-config utility to support forced credential rotation:

  • Redis password
  • MQTT password
  • Vault master key?
  • Consul tokens?
  • JWT signature keys?
@bnevis-i bnevis-i added the enhancement New feature or request label Nov 7, 2022
@bnevis-i bnevis-i changed the title Enable forced credential rotation in secrets-config utility Enable forced credential rotation in secrets-config utility [ossf silver] Nov 7, 2022
@github-project-automation github-project-automation bot moved this to New Issues in Technical WG Jul 30, 2024
@jumpingliu jumpingliu moved this from New Issues to Icebox in Technical WG Jul 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
Status: Icebox
Development

No branches or pull requests

1 participant