Hi All,
I am working on the encryption piece for our project and was hoping I could validate my use cases / Vault approach & questions with this list
We are building a web and native app that will contain PII. PII will include name, birthday, home address, and tokens representing savings/checking accounts that are given to us by our financial partner. (In the future we will also have tokenized credit card information but that will be in 2017)
We were originally going to be hosted on AWS and I was going to leverage their KMS/S3 encryption, specifically this setup mentioned in their security best practices document: Amazon S3 supports server-side encryption of user data. Server-side encryption is transparent side to the end user. AWS generates a unique encryption key for each object, and then encrypts the object using AES-256. The encryption key is then encrypted itself using AES-256-with a master key that is stored in a secure location. The master key is rotated on a regular basis.
We are moving hosting to a secure host: Armor (formerly firehost), so losing some AWS magic sauce. The whys are outside the scope of this thread but if anyone has experience with them I'd love to hear it!
I'd like to use Vault to encrypt my data and I really liked the idea of having separate keys per user.
The questions I have are:
Thanks and much appreciated
--
This mailing list is governed under the HashiCorp Community Guidelines - https://www.hashicorp.com/community-guidelines.html. Behavior in violation of those guidelines may result in your removal from this mailing list.
GitHub Issues: https://github.com/hashicorp/vault/issues
IRC: #vault-tool on Freenode
---
You received this message because you are subscribed to a topic in the Google Groups "Vault" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/vault-tool/AcZVZIoMb9c/unsubscribe.
To unsubscribe from this group and all its topics, send an email to vault-tool+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/vault-tool/ac7b4b05-ecde-4c3d-9700-b96de9c3e23f%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
This mailing list is governed under the HashiCorp Community Guidelines - https://www.hashicorp.com/community-guidelines.html. Behavior in violation of those guidelines may result in your removal from this mailing list.
GitHub Issues: https://github.com/hashicorp/vault/issues
IRC: #vault-tool on Freenode
---
You received this message because you are subscribed to a topic in the Google Groups "Vault" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/vault-tool/AcZVZIoMb9c/unsubscribe.
To unsubscribe from this group and all its topics, send an email to vault-tool+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/vault-tool/CAORe8GHzU%3D56r%2BThc1TwQRw1t7tDByj2fsa%2BeSSOZNXG%2BuVeXw%40mail.gmail.com.