Details
-
New Feature
-
Status: Resolved
-
Major
-
Resolution: Abandoned
-
1.2.0
-
None
Description
Similar to the KeyProvider interface and various backing implementations for the EncryptedWriteAheadProvenanceRepository, a generic KeyManagementControllerService should be made available so that other controller services, reporting tasks, and processors can reference it and retrieve the necessary keys to perform their cryptographic operations.
It can be backed by a variety of implementations (file-based, static, database, HSM, etc.).
It should have extensive auditing and granular access controls to restrict both user interaction and component interaction.
Attachments
Issue Links
- depends upon
-
NIFI-4139 Refactor KeyProvider interface from provenance module to framework-level service
- Resolved
- Is contained by
-
NIFI-5458 Improve NiFi TLS and certificate management
- Resolved
- is depended upon by
-
NIFI-3889 EncryptContent processor should add encryption metadata as attributes
- Resolved
-
NIFI-3929 Allow external key management for EncryptContent processor
- Resolved
- is related to
-
NIFI-6617 Implement Encrypted Repository Shared Configuration
- Resolved
-
NIFI-1995 Support keystores with multiple certificates by exposing alias selection in configuration
- Open
- relates to
-
NIFI-10667 Add Private Key Controller Service
- Resolved