Jad Boutros | |
| Co-Founder, CEO | |
| 1.415.999.5299 | |
| San Francisco, CA | |
| terratrue.com | |
--
You received this message because you are subscribed to the Google Groups "tink-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to tink-users+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/tink-users/CAMkz9zEkqi5ny-xkMGiXA9h-%2Bt_OtUL6tOg1t%2BmKYukmhF%3D_Wg%40mail.gmail.com.
On Wed, Jun 10, 2020 at 12:14 PM Jad Boutros <j...@terratrue.com> wrote:Hi Folks,Starting to try out Tink/Tinkey for Java on Google App Engine. Thanks for developing this platform/library.When Google Secret Manager came out, I converted to it from KMS as it met my needs for storage for secrets and had a much simpler interface (IMHO). You provide support for encrypting keysets in KMS but it means we still have to package the encrypted keyset in source code and deploy it with our application. I imagine it should be possible for us to instead store the (plaintext) keysets in Secret Manager and get it from there when the application starts. That way, we don't need to encrypt with KMS and also package with the application as well.Unless I am misunderstanding something, since Tinkey provides key rotation support, you're not using the one that comes with Google Cloud KMS so is there any good reason you think for integrating keysets with KMS as opposed to going the simpler route of putting them in Secret Manager directly in plaintext in JSON format?Hi Jad!I recommend SM, as it's more aligned with our future plans for key management on GCP.
Don't quote me on this, but eventually I think SM will add support for CMEK. This means you'll get Cloud KMS integration for free.
I have a plan to add to Tink native support for SM. For example, I want to provide a SecretManagerKeysetHandle that loads and auto-refresh keys from SM. This should be shipped in Tink 1.5.0.
Next, I think it'd be great if SM provides native support for Tink keysets. Users can tell SM "create a keyset from this key template and rotate it according to this schedule" and the rest will be handled by SM. We had some discussion about this, but there's still no concrete plan, so it may never happen. However, I want to bring this up to see if you think it's useful.
Cheers,Thai.--
You received this message because you are subscribed to the Google Groups "tink-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to tink-users+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/tink-users/CAMkz9zEkqi5ny-xkMGiXA9h-%2Bt_OtUL6tOg1t%2BmKYukmhF%3D_Wg%40mail.gmail.com.
--