[Openstack-security] [openstack/nova] SecurityImpact review request change I871af4018f99ddfcc8408708bdaaf480088ac477
    gerrit2 at review.openstack.org 
    gerrit2 at review.openstack.org
       
    Fri Aug 15 15:47:09 UTC 2014
    
    
  
Hi, I'd like you to take a look at this patch for potential
SecurityImpact.
https://review.openstack.org/40467
Log:
commit 7453c344214664cfec75bc8494b755914863e5c8
Author: Daniel Genin <Daniel.Genin at jhuapl.edu>
Date:   Wed Aug 13 12:52:52 2014 -0400
    Adds ephemeral storage encryption for LVM back-end images
    
    This patch adds ephemeral storage encryption for LVM back-end instances.
    Encryption is implemented by passing all data written to and read from
    the logical volumes through a dm-crypt layer. Most instance operations
    such as pause/continue, suspend/resume, reboot, etc. are supported.
    Snapshots are also supported but are not encrypted at present. VM rescue
    and migration are not supported at present.
    
    The proposed code provides data-at-rest security for all ephemeral
    storage disks, preventing access to data while an instance is
    shut down, or in case the compute host is shut down while an instance is
    running.
    
    Options controlling the encryption state, cipher and key size are
    specified in the "ephemeral_storage_encryption" options group. The boolean
    "enabled" option turns encryption on and off and the "cipher" and "key_size"
    options specify the cipher and key size, respectively.
    
    Note: depends on cryptsetup being installed.
    
    Implements: blueprint lvm-ephemeral-storage-encryption
    Change-Id: I871af4018f99ddfcc8408708bdaaf480088ac477
    DocImpact
    SecurityImpact
    
    
More information about the Openstack-security
mailing list