divviup / divviup/janus

Taskprov: determine secrets rotation strategy

Open
#1,685 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Rust
Stars
70
Forks
16
Avg merge
4h 36m
Merged PRs (30d)
30

Description

There are several secrets whose lifecycle needs to be considered:

  • Aggregator auth tokens: changes need to be communicated to and kept in sync with the peer.
  • Collector auth tokens, if operating as the leader.
  • VDAF verify key init: needs to be kept in sync with the peer for new tasks to derive the same VDAF verify key.

Relevant discussion: https://github.com/divviup/janus/pull/1675#discussion_r1286300929

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the linked discussion on pull request 1675, then trace how the issue's aggregator tokens, collector tokens, and VDAF verify-key initialization are handled. Done means an agreed rotation strategy covers each secret's lifecycle and keeps required peer state synchronized.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
authentication, cryptography, distributed-systems, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.