fleetdm / fleet

Open-source platform for IT, security, and infrastructure teams. (Linux, macOS, Chrome, Windows, cloud, data center)
https://fleetdm.com
Other
3.15k stars 431 forks source link

Do not delete Escrowed keys if a host disk is encrypted #24103

Open sharon-fdm opened 17 hours ago

sharon-fdm commented 17 hours ago

Goal

User story
As an admin for my org,
I want escrowed disk encryption keys not to be deleted as long as the host is still encrypted,
so that I can recover the key if needed.

Key result

When hosts are moved to a team that has disk encryption off, if an escrow key exists it will be deleted. This behaviour should be changed. As long as the host is encrypted, do not delete the key.

Original requests

Context

Changes

Product

Engineering

ℹ️  Please read this issue carefully and understand it. Pay special attention to UI wireframes, especially "dev notes".

QA

Risk assessment

Manual testing steps

  1. Step 1
  2. Step 2
  3. Step 3

Testing notes

Confirmation

  1. [ ] Engineer (@____): Added comment to user story confirming successful completion of QA.
  2. [ ] QA (@____): Added comment to user story confirming successful completion of QA.
sharon-fdm commented 17 hours ago

@noahtalerman, I assigned to you to see if you have specific requirements.