17e0087e43
Adds support for the Thales and ATOS client software. Change-Id: I79f8608431fecc58c8bdeba2de4a692a7ee388e9 Co-Authored-By: Douglas Mendizabal <dmendiza@redhat.com>
30 lines
1.3 KiB
YAML
30 lines
1.3 KiB
YAML
# A Heat environment file to enable the barbican PKCS11 crypto backend. Note
|
|
# that barbican needs to be enabled in order to use this.
|
|
parameter_defaults:
|
|
# In order to use this backend, you need to uncomment these values and
|
|
# provide the appropriate values.
|
|
#
|
|
# BarbicanPkcs11CryptoLogin: Password to login to PKCS11 session
|
|
# BarbicanPkcs11CryptoSlotId: Slot Id for the HSM
|
|
# BarbicanPkcs11CryptoGlobalDefault: Whether this plugin is the global default plugin
|
|
|
|
BarbicanPkcs11CryptoLibraryPath: '/usr/lib64/libnethsm.so'
|
|
BarbicanPkcs11CryptoEncryptionMechanism: 'CKM_AES_CBC'
|
|
BarbicanPkcs11CryptoHMACKeyType: 'CKK_GENERIC_SECRET'
|
|
BarbicanPkcs11CryptoHMACKeygenMechanism: 'CKM_GENERIC_SECRET_KEY_GEN'
|
|
BarbicanPkcs11CryptoMKEKLabel: 'barbican_mkek_0'
|
|
BarbicanPkcs11CryptoMKEKLength: 32
|
|
BarbicanPkcs11CryptoHMACLabel: 'barbican_hmac_0'
|
|
BarbicanPkcs11CryptoATOSEnabled: true
|
|
BarbicanPkcs11CryptoEnabled: true
|
|
ATOSVars:
|
|
atos_client_working_dir: /tmp/atos_client_install
|
|
# atos_client_iso_location:
|
|
# atos_client_iso_name:
|
|
# atos_client_cert_location:
|
|
# atos_client_key_loaction:
|
|
# atos_hsm_ip_address:
|
|
|
|
resource_registry:
|
|
OS::TripleO::Services::BarbicanBackendPkcs11Crypto: ../puppet/services/barbican-backend-pkcs11-crypto.yaml
|