5305c439d4
* Update init.mdx Updated operator init documentation to try to avoid steering customers towards running Auto Unseal seals with recovery-shares=1 and recovery-threshold=1. This is a bad security posture, as it can allow a single user with access to that recovery share to create root tokens and do other very sensitive tasks. Also rewrote parts of the HSM/KMS Options section to indicate that recovery-related options are not solely for HSM-mode Vault but are for ANY Auto Unseal seal. * Update website/content/docs/commands/operator/init.mdx Adding an appropriate number of recovery-pgp-keys Co-authored-by: Yoko <yoko@hashicorp.com> Co-authored-by: Yoko <yoko@hashicorp.com> |
||
---|---|---|
.. | ||
generate-root.mdx | ||
index.mdx | ||
init.mdx | ||
key-status.mdx | ||
migrate.mdx | ||
raft.mdx | ||
rekey.mdx | ||
rotate.mdx | ||
seal.mdx | ||
step-down.mdx | ||
unseal.mdx | ||
usage.mdx |