3 ms·
Assuming you arn't trying to go for top security, and just want a way to keep things safe from leaking due to errors and the such why not just make use of the
by RubyPinch 12y ago
Assuming you arn't trying to go for top security, and just want a way to keep things safe from leaking due to errors and the such
why not just make use of the OS's secrets store? for example, like how https://pypi.python.org/pypi/keyring https://pypi.python.org/pypi/keyring operates
- riobard 12y agoI would love to know more about this, but AFAIK OS secret stores are mostly a desktop-concept that requires a logged-in user (whose login password is used to decrypt the secret store). On a deployment server, you don't have those.
- rbanffy 12y agoIt should be easy to set up such a key store on server setup or startup. The downside is that, as always, if anyone has access to the user, they can decrypt the keys.