Storage
Store and migrate certificate assets across Sia and AWS using provider managed or self managed storage.
Overview
Each X.509 asset lives within a single storage provider at any given point in time. SecuriTLS lets you use, store, and migrate X.509 assets between multiple storage providers.
Provider managed storage
Provider managed storage is managed and provided by SecuriTLS.
Self managed storage
Self managed storage is managed by you and is available to Solo, Team, Business, and Enterprise users. Free workspaces use provider managed storage.
Self managed storage controls where encrypted certificate assets are stored. It does not, by itself, change the key custody model. Storage encryption still uses a SecuriTLS generated DEK unless Business or Enterprise BYOK is configured.
Sia storage
Built on Sia, SecuriTLS uses decentralized storage by default. Sia distributes fragmented, encrypted data across a global network of independent storage providers. Data is not stored on the blockchain.
- Label or name optional
- Bucket name
- API endpoint
- API password sensitive
AWS storage
AWS self managed storage supports access key based setup and role based setup.
- Label or name optional
- AWS region
- Bucket name
Role based AWS setup
Role based setup uses a cross account IAM role that SecuriTLS can assume. The role can optionally require an external ID. Use your bucket level and object level S3 permissions as described in the README.