James Muehlner created GUACAMOLE-1656:
-----------------------------------------

             Summary: Allow per-user KSM Vault configurations
                 Key: GUACAMOLE-1656
                 URL: https://issues.apache.org/jira/browse/GUACAMOLE-1656
             Project: Guacamole
          Issue Type: Improvement
          Components: guacamole-vault
            Reporter: James Muehlner


Users should have the ability to configure their own Keeper Secrets Manager 
vault, to provide secrets to fill in any gaps left by the 
administrator-configured KSM vault.

For security reasons:
 * User-provided vaults should not be allowed to override any secrets defined 
in administratively defined vaults
 * Allowing users to provide KSM configs should be disabled by default, and 
only enabled if enabled in the guacamole.properties config file
 * Allowing user vaults to provide secrets should be disabled by default for 
connections, and should only be allowed if explicitly enabled on a 
per-connection basis.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to