- From: Maven User <
>
- To: chef <
>
- Subject: [chef] encrypted databag sadness
- Date: Fri, 13 Jul 2012 10:48:12 -0700
Hi all -
We're contemplating storing the values of some ssl keys and certificates in an encrypted databag, but I have a couple of questions:
1 - Is there a way to have "local" encrypted databags? I was able to create an encrypted databag on our chef server, list the encrypted values and copy/pasted them into a local json file. Using the key that will successfully decrypt the values from the databag stored on the server, I cannot decrypt the same values out of the local .json file. Shouldn't that work?
2 - What is the standard way to get the key for decrypting databag values on a machine? We're trying to do this in an automated fashion and haven't found a place that best suits automated bootstrapping - what are people doing?
3 - Some of the crt and key values are escape characters - is it possible to escape them without screwing up the actual values?
Thanks a million :-/
- [chef] encrypted databag sadness, Maven User, 07/13/2012
Archive powered by MHonArc 2.6.16.