neicnordic / sensitive-data-archive

https://neic-sda.readthedocs.io
GNU Affero General Public License v3.0
3 stars 7 forks source link

[ingest] Support multiple encryption keys #787

Open nanjiangshu opened 6 months ago

nanjiangshu commented 6 months ago

Main user story

As a security conscious user of the sensitive data arcive, I want to see that the archive can rotate encryption keys so that security can be maintained.

Sub user story

As an sda-dev I want to implement multiple-key support for the ingest service so that repository key rotation can be enabled.

Description

Acceptance criteria

Extra information

Note: key rotation miro board here

Related issue for the verify service #1087.

blankdots commented 6 months ago

it would be good if this is left flexible/configurable as we do already have a mechanism to do that with https://github.com/CSCfi/c4gh-transit