Re: Security Policy was: Query regarding where to store encryption keys

2012-07-01 Thread John Kinsella
t; >> Thanks. >> >> -Clement >> >> -----Original Message----- >> From: David Nalley [mailto:da...@gnsa.us] >> Sent: Friday, June 29, 2012 10:44 AM >> To: cloudstack-dev@incubator.apache.org >> Subject: Security Policy was: Query regarding wher

Re: Security Policy was: Query regarding where to store encryption keys

2012-06-29 Thread John Kinsella
> Thanks. > > -Clement > > -Original Message- > From: David Nalley [mailto:da...@gnsa.us] > Sent: Friday, June 29, 2012 10:44 AM > To: cloudstack-dev@incubator.apache.org > Subject: Security Policy was: Query regarding where to store encryption keys > > I don&

RE: Security Policy was: Query regarding where to store encryption keys

2012-06-29 Thread Clement Chen
: cloudstack-dev@incubator.apache.org Subject: Security Policy was: Query regarding where to store encryption keys I don't want to lose track of this conversation. I think John's proposal makes a lot of sense. What is actionable out of this? --David On Fri, Jun 22, 2012 at 8:13 PM, Joh

Security Policy was: Query regarding where to store encryption keys

2012-06-29 Thread David Nalley
I don't want to lose track of this conversation. I think John's proposal makes a lot of sense. What is actionable out of this? --David On Fri, Jun 22, 2012 at 8:13 PM, John Kinsella wrote: > Concur on both. I've been in an appsec mode recently and sending people to > the OWASP site so that came