Breaking News: Grepper is joining You.com. Read the official announcement!
Check it out

Seal and Unseal

Sumit Rawal answered on June 5, 2023 Popularity 1/10 Helpfulness 1/10

Contents


More Related Answers


Seal and Unseal

0

Vault starts in a sealed state, meaning it knows where to access the data, and

how, but can’t decrypt it

• Almost no operations are possible when Vault is in a sealed state (only status

check and unsealing are possible)

• Unsealing Vault means that a node can reconstruct the master key in order to

decrypt the encryption key, and ultimately and read the data

• After unsealing, the encryption key is stored in memory

Sealing Vault means Vault “throws away” the encryption key and requires

another unseal to perform any further operations

• Vault will start in a sealed state – you can also manually seal it via UI, CLI, or API

• When would I seal Vault?

• Key shards are inadvertently exposed

• Detection of a compromise or network intrusion

• Spyware/malware on the Vault nodes 

Popularity 1/10 Helpfulness 1/10 Language whatever
Source: Grepper
Tags: seal whatever
Link to this answer
Share Copy Link
Contributed on Jun 05 2023
Sumit Rawal
0 Answers  Avg Quality 2/10


X

Continue with Google

By continuing, I agree that I have read and agree to Greppers's Terms of Service and Privacy Policy.
X
Grepper Account Login Required

Oops, You will need to install Grepper and log-in to perform this action.