Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Run pscipher -buildkey to prevent V1.1 keys from being used #14

Open
iversond opened this issue Oct 17, 2017 · 2 comments
Open

Run pscipher -buildkey to prevent V1.1 keys from being used #14

iversond opened this issue Oct 17, 2017 · 2 comments

Comments

@iversond
Copy link
Contributor

No description provided.

@iversond
Copy link
Contributor Author

Based on recent security disclosures, the default V1.1 keys should not be used when encrypting passwords during builds.

@ericbisme
Copy link
Collaborator

Agreed! We're going to run in to some issues of ordering. For everything else this module does it needs to run after the delivered deployment so that all the pieces exist. By that point the passwords have already been encrypted using the delivered V1.1 keys. We may end up digging in to the type/provider to do this properly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants