1
0
mirror of https://github.com/minio/docs.git synced 2025-07-30 07:03:26 +03:00

Apply suggestions from code review

Co-authored-by: Andreas Auernhammer <aead@mail.de>
This commit is contained in:
Ravind Kumar
2021-05-03 17:00:44 -04:00
committed by Ravind Kumar
parent 85dbf58bd9
commit 5fe66d4f79
2 changed files with 5 additions and 7 deletions

View File

@ -277,8 +277,7 @@ Key Management Service and Encryption
The private key associated to the the :envvar:`MINIO_KMS_KES_CERT_FILE` The private key associated to the the :envvar:`MINIO_KMS_KES_CERT_FILE`
x.509 certificate to use when authenticating to the KES server. x.509 certificate to use when authenticating to the KES server.
The KES server requires clients to present both their certificate and The KES server requires clients to present their certificate for performing mutual TLS (mTLS).
private key for performing mutual TLS (mTLS).
See the :minio-git:`KES wiki <kes/wiki/Configuration#policy-configuration>` See the :minio-git:`KES wiki <kes/wiki/Configuration#policy-configuration>`
for more complete documentation on KES access control. for more complete documentation on KES access control.
@ -286,8 +285,7 @@ Key Management Service and Encryption
.. envvar:: MINIO_KMS_KES_CERT_FILE .. envvar:: MINIO_KMS_KES_CERT_FILE
The x.509 certificate to present to the KES server. The x.509 certificate to present to the KES server.
The KES server requires clients to present both their certificate and The KES server requires clients to present their certificate and for performing mutual TLS (mTLS).
private key for performing mutual TLS (mTLS).
The KES server computes an The KES server computes an
:minio-git:`identity <kes/wiki/Configuration#policy-configuration>` :minio-git:`identity <kes/wiki/Configuration#policy-configuration>`
@ -301,7 +299,7 @@ Key Management Service and Encryption
.. envvar:: MINIO_KMS_KES_KEY_NAME .. envvar:: MINIO_KMS_KES_KEY_NAME
The name of an external ke to retrieve from the Key Management System (KMS) The name of an external key at the Key Management System (KMS) to perform en/decryption operations
configured on the KES server. MinIO uses this key for supporting configured on the KES server. MinIO uses this key for supporting
server-side encryption of objects (SSE-S3) and MinIO backend encryption. server-side encryption of objects (SSE-S3) and MinIO backend encryption.

View File

@ -193,7 +193,7 @@ The command uses the following options:
Replace this value with a unique, random, and long string. Replace this value with a unique, random, and long string.
* - :envvar:`MINIO_KMS_SECRET_KEY` * - :envvar:`MINIO_KMS_SECRET_KEY`
- The key to use for encrypting the MinIO backend (users, groups, - The key to use for encrypting the MinIO backend (S3 objects, users, groups,
policies, and server configuration). policies, and server configuration).
Replace this value with a 256-bit base64-encrypted string: Replace this value with a 256-bit base64-encrypted string:
@ -424,4 +424,4 @@ install using `pkg <https://github.com/freebsd/pkg>`__:
pkg install minio pkg install minio
sysrc minio_enable=yes sysrc minio_enable=yes
sysrc minio_disks=/path/to/disks sysrc minio_disks=/path/to/disks
service minio start service minio start