Comment on [deleted]

Eknz@lemmy.eknz.org ⁨5⁩ ⁨days⁩ ago

Ironically, the passphrase for the encryption wouldn’t be encrypted in this scenario as claims can be decoded from the token payload if intercepted. It would also probably be stored as-is server side as well. Claims aren’t designed as secrets.

Perhaps you could authorise a request to an actual secrets manager via oidc though, allowing the volume to be unlocked.

source
Sort:hotnewtop