[openstack-dev] Volume encryption

Caitlin Bestler Caitlin.Bestler at nexenta.com
Thu Mar 28 19:57:06 UTC 2013



Paul Sarin-Pollet wrote:

> Dou you think it could be possible to add an option to let the user enter his own key ?
> The key would not be stored by the CSP and would be under the user responsability.


If the user holds and is responsible for the key, why would the user want to communicate
the key over the network for the purpose of concentrating the encrypt/decrypt heavy lifting
onto the centralized storage server, rather than doing the encrypting/decrypting itself?

When the users do not maintain the key is when it makes sense to do the encryption/decryption
on the storage server.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstack.org/pipermail/openstack-dev/attachments/20130328/05f26419/attachment.html>


More information about the OpenStack-dev mailing list