mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-19 11:06:17 +00:00
fix(kms): unify persisted SSE data key envelopes (#5343)
* feat(kms): implement secure handling of static KMS secret keys and enhance encryption context validation * feat: enhance local SSE DEK handling with JSON envelope format and versioning
This commit is contained in:
@@ -214,9 +214,18 @@ pub struct StaticConfig {
|
||||
/// Key identifier (name) for the single configured key
|
||||
pub key_id: String,
|
||||
/// Base64-encoded 32-byte AES-256 key material (zeroed on drop)
|
||||
#[serde(skip_serializing, default)]
|
||||
pub secret_key: String,
|
||||
}
|
||||
|
||||
impl Drop for StaticConfig {
|
||||
fn drop(&mut self) {
|
||||
use zeroize::Zeroize;
|
||||
|
||||
self.secret_key.zeroize();
|
||||
}
|
||||
}
|
||||
|
||||
impl fmt::Debug for StaticConfig {
|
||||
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
|
||||
f.debug_struct("StaticConfig")
|
||||
@@ -1054,6 +1063,21 @@ mod tests {
|
||||
assert!(serialized.contains("persisted-token-secret"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn static_kms_config_serialization_does_not_expose_key_material() {
|
||||
use base64::Engine as _;
|
||||
|
||||
let encoded_key = base64::engine::general_purpose::STANDARD.encode([0x5au8; 32]);
|
||||
let config = KmsConfig::static_kms("static-key".to_string(), encoded_key.clone());
|
||||
|
||||
let serialized = serde_json::to_string(&config).expect("static KMS config should serialize");
|
||||
|
||||
assert!(
|
||||
!serialized.contains(&encoded_key),
|
||||
"persisted static KMS configuration must not contain plaintext key material"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_config_validation() {
|
||||
let mut config = KmsConfig {
|
||||
|
||||
Reference in New Issue
Block a user