-
Type:
Improvement
-
Resolution: Unresolved
-
Priority:
Major - P3
-
None
-
Affects Version/s: None
-
Component/s: None
-
None
-
Server Security
-
None
-
None
-
None
-
None
-
None
-
None
-
None
The current arch guide doesn't adequately explain the following:
- keystore schema versions (what's v0 and v1, why two versions?)
- what happens during master key rollover
- what key is used to encrypt the keystore tables (or whether it's even encrypted at all??)
- what the keystore.metadata file (and its flavors: keystore.metadata-invalidated-<timestamp> and keystore.metadata-initializing) are for.
- the names of special keys ".system" and ".master"
- what the ".system" key is used for?
- bootstrap sequence for initializing the ESE on server startup