pbatko-da bd01a211f4
[DPP-418] Protect Participant TLS keys (#10629)
Adding support for accepting server's private key as an encrypted file (since storing unencrypted private key in a file system might be a risk).

Encrypted private key is assumed to be encrypted using AES or similar algorithm. The details necessary to decrypt it are be obtained from a secrets server over HTTP as JSON document. The URL to secret's server is supplied through the new `--secrets-url` CLI parameter.

One can supply private in either plaintext (old behavior) or ciphertext: if a private key's file ends with .enc suffix it is assumed to be ciphertext. Otherwise it is assumed to be plain text.

- [DPP-418] [Participant] Add support for supplying server's private key as an encrypted file and then decrypting it with the help of a secrets server.
2021-08-30 09:24:52 +02:00

72 lines
1.9 KiB

# Copyright (c) 2021 Digital Asset (Switzerland) GmbH and/or its affiliates. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
name = "jwt",
srcs = glob(["src/main/scala/**/*.scala"]),
scala_deps = [
scalacopts = lf_scalacopts,
tags = ["maven_coordinates=com.daml:jwt:__VERSION__"],
versioned_scala_deps = {
"2.12": [
visibility = ["//visibility:public"],
runtime_deps = [
deps = [
name = "jwt-bin",
main_class = "com.daml.jwt.Main",
scalacopts = lf_scalacopts,
runtime_deps = [
deps = [
name = "tests",
size = "medium",
srcs = glob(["src/test/scala/**/*.scala"]),
resources = glob(["src/test/resources/**/*"]),
scala_deps = [
scalacopts = lf_scalacopts,
deps = [