patches and low-level development discussion
 help / color / mirror / code / Atom feed
blob 26fe273cb6fd338ef07deead8a36f0f2027a0a07 554 bytes (raw)
name: Documentation/decisions/004-data-at-rest-encryption.adoc 	 # note: path name is non-authoritative(*)

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
 
= 004 Data at Rest Encryption
:page-parent: Architecture Decision Records
:page-grand_parent: Explanation

// SPDX-FileCopyrightText: 2022 Unikie
// SPDX-License-Identifier: GFDL-1.3-no-invariants-or-later OR CC-BY-SA-4.0

== Status

Proposed

== Context

For privacy protection, encryption of user data at rest is required.

== Decision

User data is encrypted.

== Consequences

Spectrum needs to come with enough software to get the encryption key
via different methods (password, usb, fido, etc.)  Can we use dm-crypt
for everything instead of LUKS?

debug log:

solving 26fe273 ...
found 26fe273 in https://spectrum-os.org/git/spectrum

(*) Git path names are given by the tree(s) the blob belongs to.
    Blobs themselves have no identifier aside from the hash of its contents.^

Code repositories for project(s) associated with this public inbox

	https://spectrum-os.org/git/doc
	https://spectrum-os.org/git/mktuntap
	https://spectrum-os.org/git/spectrum
	https://spectrum-os.org/git/ucspi-vsock

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).