Bug 1379015 - [RFE] Support for Clevis
Summary: [RFE] Support for Clevis
Keywords:
Status: CLOSED DEFERRED
Alias: None
Product: Red Hat Ceph Storage
Classification: Red Hat Storage
Component: RADOS
Version: 2.0
Hardware: Unspecified
OS: Unspecified
unspecified
medium
Target Milestone: rc
: 4.0
Assignee: Josh Durgin
QA Contact: ceph-qe-bugs
URL:
Whiteboard:
Depends On: 1300697
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-09-23 23:47 UTC by Neil Levine
Modified: 2022-02-21 18:06 UTC (History)
8 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-02-11 16:09:32 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Ceph Project Bug Tracker 17493 0 None None None 2016-10-04 07:06:43 UTC

Description Neil Levine 2016-09-23 23:47:51 UTC
Clevis is a client-side, pluggable key management tool that has been developed as part of the Tang project. 

https://github.com/latchset/clevis
https://github.com/latchset/tang

It can interact with any arbitrary key escrow system as well as the Tang server. We should insert it into our ceph-disk and MON keystore workflow so we can later extend it to Tang or allow customers to insert plugins to interact with their own key management systems.

My understanding is Clevis is less mature than Tang but once packages are made available we should look to start the integration so we can help with the development of the project. 

Further details at: https://www.youtube.com/watch?v=p_M0YEE-esA

Comment 4 Loic Dachary 2016-12-08 06:51:59 UTC
Tests added upstream and scheduled for backport to jewel.

Comment 5 Loic Dachary 2016-12-08 06:52:35 UTC
Ooops, wrong bz, sorry about that.

Comment 7 Neil Levine 2017-07-18 20:56:56 UTC
Gregory, has any analysis of what is needed to implement the integration been done? This is a heavily requested feature so would like to know if it can be a candidate for a minor release on v3.

Comment 8 Nathaniel McCallum 2017-07-18 21:01:40 UTC
Please include me in any planning sessions. Thanks!

Comment 9 Christina Meno 2017-07-31 16:44:09 UTC
Neil,

I know nothing of what'd take to implement this, first I've heard of it is when I proposed it for 4.0 during scrub. 

I will review the included links to see if we could get it in 3.X
cheers

Comment 10 Josh Durgin 2019-02-11 16:09:32 UTC
Not relevant in the near term.


Note You need to log in before you can comment on or make changes to this bug.