open-vault/website/content/docs/commands/operator
Jacob Friedman 5305c439d4
Update init.mdx (#11044)
* Update init.mdx

Updated operator init documentation to try to avoid steering customers towards running Auto Unseal seals with recovery-shares=1 and recovery-threshold=1. This is a bad security posture, as it can allow a single user with access to that recovery share to create root tokens and do other very sensitive tasks.

Also rewrote parts of the HSM/KMS Options section to indicate that recovery-related options are not solely for HSM-mode Vault but are for ANY Auto Unseal seal.

* Update website/content/docs/commands/operator/init.mdx

Adding an appropriate number of recovery-pgp-keys

Co-authored-by: Yoko <yoko@hashicorp.com>

Co-authored-by: Yoko <yoko@hashicorp.com>
2021-03-04 15:57:47 -08:00
..
generate-root.mdx Implement MDX Remote (#10581) 2020-12-17 16:53:33 -05:00
index.mdx Implement MDX Remote (#10581) 2020-12-17 16:53:33 -05:00
init.mdx Update init.mdx (#11044) 2021-03-04 15:57:47 -08:00
key-status.mdx Implement MDX Remote (#10581) 2020-12-17 16:53:33 -05:00
migrate.mdx Implement MDX Remote (#10581) 2020-12-17 16:53:33 -05:00
raft.mdx Implement MDX Remote (#10581) 2020-12-17 16:53:33 -05:00
rekey.mdx Implement MDX Remote (#10581) 2020-12-17 16:53:33 -05:00
rotate.mdx Implement MDX Remote (#10581) 2020-12-17 16:53:33 -05:00
seal.mdx Implement MDX Remote (#10581) 2020-12-17 16:53:33 -05:00
step-down.mdx Implement MDX Remote (#10581) 2020-12-17 16:53:33 -05:00
unseal.mdx Implement MDX Remote (#10581) 2020-12-17 16:53:33 -05:00
usage.mdx Implement MDX Remote (#10581) 2020-12-17 16:53:33 -05:00