Has anybody seen my keys? A key-hierarchy strategy for rack-level security(rfd.shared.oxide.computer) |
Has anybody seen my keys? A key-hierarchy strategy for rack-level security(rfd.shared.oxide.computer) |
https://oxide-and-friends.transistor.fm/episodes/building-a-...
That tension between needing both secrets for ZFS rekey and only serving shares for the committed epoch is a real distributed systems headache and this is a clean way out of it