Bug 1967148

Summary: Test/document use of 512 bit volume encryption keys
Product: Red Hat OpenStack Reporter: Eric Harney <eharney>
Component: openstack-cinderAssignee: Eric Harney <eharney>
Status: NEW --- QA Contact: Evelina Shames <eshames>
Severity: medium Docs Contact: Andy Stillman <astillma>
Priority: medium    
Version: 16.2 (Train)CC: astillma, lmarsh, ltoscano
Target Milestone: ---Keywords: TestOnly, Triaged
Target Release: ---Flags: ifrangs: needinfo? (eharney)
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Eric Harney 2021-06-02 13:58:05 UTC
https://access.redhat.com/documentation/en-us/red_hat_openstack_platform/16.1/html/storage_guide/ch-cinder#section-volumes_advanced_encryption

The storage guide currently documents use of 256 bit encryption keys.

Barbican now allows us to store 512 bit keys when using aes-xts, which we should support for Cinder volumes in OSP:  https://review.opendev.org/c/openstack/barbican/+/577096