#7 Initial design for signing as a service
Opened by vakwetu. Modified
alee_branch_2  into  master

Download 7.patch
no initial comment

Although migration generally needs to occur before its usage, DRMTool needs to be thoroughly tested with this new KRA to be certain that re-keying, etc. can still be performed.

As discussed on IRC, a migration strategy from previous versions of KRA must be considered (possibly via scripts).
This did not previously exist in the document, as the design is still in flux at the time of this writing.

As this design only seeks to potentially add some new fields to the KRA record (not delete/modify the usage of any existing fields), the migration should hopefully not be that difficult.

Additional consideration must be given to the various migration scenarios. For example, will we have cases where there are actually Barbican, IPA, and CS secrets mixed up, or will they all be just CS, just Barbican, and just IPA?

I think we can compute hashes of large files in pieces. Of course the whole thing will have to be uploaded, but not saved in its entirety.

Pull-Request has been updated

Metadata