[EVM-370] Added --insecure flag to both ibft and polybft #1182
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
When initializing the chain and using a local storage, private keys are stored as a plaintext format by default, in a local folder the operator has defined during the
secrets init
orpolybft-secrets init
stage.This PR adds the
--insecure
flag as mandatory in order to store private keys unencrypted.If the operator tries to run
secrets init
orpolybft-secrets init
command without--insecure
flag, the erroruse a secrets backend, or supply an --insecure flag...
will be presented.When
--insecure
flag is used for storing the secrets locally, the following warning will be presented:[WARNING: INSECURE LOCAL SECRETS - SHOULD NOT BE RUN IN PRODUCTION]
as storing secrets using this method, presents a high security risk and should not be used in production environments.
Changes include
Checklist
Testing
Manual tests
Run
secrets init --data-dir <folder>
orpolybft-secrets init --data-dir <folder>
- it should fail with an erroruse a secrets backend, or supply an --insecure flag...
.Run
secrets init --data-dir <folder> --insecure
orpolybft-secrets init --data-dir <folder> --insecure
- it should succeed with a warning[WARNING: INSECURE LOCAL SECRETS - SHOULD NOT BE RUN IN PRODUCTION]
Additional comments
Fixes EVM-370
Fixes EDGE-1024