parameter_defaults:
SwiftEncryptionEnabled: true
ComputeExtraConfig:
nova::glance::verify_glance_signatures: true
nova::compute::verify_glance_signatures: true
BarbicanPkcs11CryptoLogin: 'sample string'
BarbicanPkcs11CryptoSlotId: '492971158'
BarbicanPkcs11CryptoGlobalDefault: true
BarbicanPkcs11CryptoLibraryPath: '/opt/nfast/toolkits/pkcs11/libcknfast.so'
BarbicanPkcs11CryptoEncryptionMechanism: 'CKM_AES_CBC'
BarbicanPkcs11CryptoHMACKeyType: 'CKK_SHA256_HMAC'
BarbicanPkcs11CryptoHMACKeygenMechanism: 'CKM_NC_SHA256_HMAC_KEY_GEN'
BarbicanPkcs11CryptoMKEKLabel: 'barbican_mkek_10'
BarbicanPkcs11CryptoMKEKLength: '32'
BarbicanPkcs11CryptoHMACLabel: 'barbican_hmac_10'
BarbicanPkcs11CryptoThalesEnabled: true
BarbicanPkcs11CryptoEnabled: true
ThalesVars:
thales_client_working_dir: /tmp/thales_client_install
thales_client_tarball_location: https://your server/CipherTools-linux64-dev-12.40.2.tgz
thales_client_tarball_name: CipherTools-linux64-dev-12.40.2.tgz
thales_client_path: linux/libc6_11/amd64/nfast
thales_client_uid: 42481
thales_client_gid: 42481
thales_km_data_location: https://your server/kmdata_post_card_creation.tar.gz
thales_km_data_tarball_name: kmdata_post_card_creation.tar.gz
thales_hsm_ip_address: 192.168.10.10
thales_rfs_server_ip_address: 192.168.10.11
thales_hsm_config_location: hsm-C90E-02E0-D947
thales_rfs_user: root
thales_rfs_key: |
-----BEGIN RSA PRIVATE KEY-----
Sample private key
-----END RSA PRIVATE KEY-----
resource_registry:
OS::TripleO::Services::BarbicanBackendPkcs11Crypto: /home/stack/tripleo-heat-templates/puppet/services/barbican-backend-pkcs11-crypto.yaml
parameter_defaults:
SwiftEncryptionEnabled: true
ComputeExtraConfig:
nova::glance::verify_glance_signatures: true
nova::compute::verify_glance_signatures: true
BarbicanPkcs11CryptoLogin: 'sample string'
BarbicanPkcs11CryptoSlotId: '492971158'
BarbicanPkcs11CryptoGlobalDefault: true
BarbicanPkcs11CryptoLibraryPath: '/opt/nfast/toolkits/pkcs11/libcknfast.so'
BarbicanPkcs11CryptoEncryptionMechanism: 'CKM_AES_CBC'
BarbicanPkcs11CryptoHMACKeyType: 'CKK_SHA256_HMAC'
BarbicanPkcs11CryptoHMACKeygenMechanism: 'CKM_NC_SHA256_HMAC_KEY_GEN'
BarbicanPkcs11CryptoMKEKLabel: 'barbican_mkek_10'
BarbicanPkcs11CryptoMKEKLength: '32'
BarbicanPkcs11CryptoHMACLabel: 'barbican_hmac_10'
BarbicanPkcs11CryptoThalesEnabled: true
BarbicanPkcs11CryptoEnabled: true
ThalesVars:
thales_client_working_dir: /tmp/thales_client_install
thales_client_tarball_location: https://your server/CipherTools-linux64-dev-12.40.2.tgz
thales_client_tarball_name: CipherTools-linux64-dev-12.40.2.tgz
thales_client_path: linux/libc6_11/amd64/nfast
thales_client_uid: 42481
thales_client_gid: 42481
thales_km_data_location: https://your server/kmdata_post_card_creation.tar.gz
thales_km_data_tarball_name: kmdata_post_card_creation.tar.gz
thales_hsm_ip_address: 192.168.10.10
thales_rfs_server_ip_address: 192.168.10.11
thales_hsm_config_location: hsm-C90E-02E0-D947
thales_rfs_user: root
thales_rfs_key: |
-----BEGIN RSA PRIVATE KEY-----
Sample private key
-----END RSA PRIVATE KEY-----
resource_registry:
OS::TripleO::Services::BarbicanBackendPkcs11Crypto: /home/stack/tripleo-heat-templates/puppet/services/barbican-backend-pkcs11-crypto.yaml
Copy to Clipboard
Copied!
Toggle word wrap
Toggle overflow