We explore the Ceph security model. Digging increasingly deeper in the stack, we examine hardening options appropriate to a variety of threat profiles. Options include defining a threat model, limiting the blast radius of an attack by implementing separate security zones, the use of encryption at rest and in-flight and FIPS 140-2 validated ciphers, hardened builds and default configuration, as well as user access controls and key management. Data retention and secure deletion are also addressed.
Speakers:
Federico Lucifredi
Connect with us:
OpenInfra Twitter: / openinfradev
OpenInfra LinkedIn: / openinfra-foundation
OpenInfra Facebook: / openinfradev
OpenInfra Website: https://openinfra.dev/
Thank you to our 2023 Headline Sponsor Wind River (https://www.windriver.com/) and our Premier Sponsor Okestro (https://www.okestro.com/)