Skip to content

Add missing handling for recording encryption configs and keys #57279

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 2 commits into
base: eriktate/refactor-encrypted-recording-protos
Choose a base branch
from

Conversation

eriktate
Copy link
Contributor

This PR adds a few missing pieces to recording encryption:

  • Use alternate labels/tags for encryption keys so they aren't automatically removed while still in use
  • Prevent cloud tenants from using manual_key_management
  • Prevent recording encryption in FIPS mode

@github-actions github-actions bot requested review from gzdunek and nklaassen July 29, 2025 19:56
@eriktate eriktate force-pushed the eriktate/refactor-encrypted-recording-protos branch from 3c160d0 to e99bcc2 Compare July 29, 2025 21:03
@eriktate eriktate force-pushed the eriktate/add-tags-to-encryption-keys branch from f454db6 to 8101eed Compare July 29, 2025 21:04
eriktate added 2 commits July 30, 2025 15:49
…usting pkcs11 host UUID check to allow for key sharing of encryption keys, preventing cloud tenants from enabling manual key management
@public-teleport-github-review-bot

@eriktate - this PR will require admin approval to merge due to its size. Consider breaking it up into a series smaller changes.

@eriktate eriktate force-pushed the eriktate/refactor-encrypted-recording-protos branch from e99bcc2 to 7b9deac Compare July 30, 2025 20:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant