aws / aws/aws-encryption-sdk-python

Preferential order of decryption

Abierto
#226 4 comentarios 1 reacción 0 asignados Ver en GitHub
requires followup
Lenguaje dominante
Python
Estrellas
255
Forks
92
Merge medio
2 d 17 h
PR fusionados (30 d)
2

Descripción

Hi amazing crypto heroes of AWS!

We are using the library to encrypt our sensitive settings in our project (passwords, API keys etc). We encrypt with two keys, one is a "development-key" and the other is the "production-key". When we decrypt in production, we would like the SDK to not use the development key, however it tries both and always fails the decrypt on the development key. I know we can set up a KmsKeyProvider to only have the ARN of the production key, but that would make our code a lot messier (having to pass it from a dynamic environment variable etc).

Is there a way to set the order of which keys will be used to decrypt when encrypting? Such to say when we encrypt we will use keys "production-key" and then "development-key". During decryption the SDK will try the first and only if it fails will go onto the second. The failure of trying to use the development key in production is taking IO and impacting our Lambda cold start times.

I feel like this feature should already be supported and maybe I am just not able to figure it out. I see that the SDK gives preferences to keys that are in the same region, but both keys are in the same region in my case 🤕

Any insight or help would be greatly appreciated!

Stay awesome and stay safe,
Mo Kamioner

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Comienza revisando KmsKeyProvider y el comportamiento existente del SDK para la selección de claves y el descifrado, incluida su preferencia por la misma región. Define cómo debe interactuar un orden explícito que priorice la clave de producción con el cifrado y el descifrado, y valida el comportamiento con el escenario reportado de dos claves y su impacto en el arranque en frío de Lambda.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
aws, python
Área
cloud, cryptography, security
Tipo de issue
Nueva funcionalidad
Dificultad
5/5
Tiempo estimado
Más de una semana
Estado de actividad
Estancado
Claridad
Bastante claro
Aptitud para principiantes
28/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.