Improve architecture guide for encrypted storage engine

    • Type: Improvement
    • Resolution: Unresolved
    • Priority: Major - P3
    • None
    • Affects Version/s: None
    • Component/s: None
    • None
    • Server Security
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      The current arch guide doesn't adequately explain the following:

      • keystore schema versions (what's v0 and v1, why two versions?)
      • what happens during master key rollover
      • what key is used to encrypt the keystore tables (or whether it's even encrypted at all??)
      • what the keystore.metadata file (and its flavors: keystore.metadata-invalidated-<timestamp> and keystore.metadata-initializing) are for.
      • the names of special keys ".system" and ".master"
      • what the ".system" key is used for?
      • bootstrap sequence for initializing the ESE on server startup

            Assignee:
            Unassigned
            Reporter:
            Erwin Pe
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: