66fe91
# /etc/custodia/custodia.conf
66fe91
66fe91
[DEFAULT]
66fe91
libdir = /var/lib/custodia
66fe91
logdir = /var/log/custodia
66fe91
rundir = /var/run/custodia
66fe91
66fe91
[global]
66fe91
debug = true
66fe91
server_socket = ${rundir}/custodia.sock
66fe91
auditlog = ${logdir}/audit.log
66fe91
66fe91
[store:sqlite]
66fe91
handler = SqliteStore
66fe91
dburi = ${libdir}/secrets.db
66fe91
table = secrets
66fe91
66fe91
[store:encrypted_sqlite]
66fe91
handler = EncryptedOverlay
66fe91
backing_store = sqlite
66fe91
master_key = ${libdir}/secrets.key
66fe91
master_enctype = A128CBC-HS256
66fe91
autogen_master_key = true
66fe91
66fe91
[auth:creds]
66fe91
handler = SimpleCredsAuth
66fe91
uid = root
66fe91
gid = root
66fe91
66fe91
[authz:paths]
66fe91
handler = SimplePathAuthz
66fe91
paths = /. /secrets
66fe91
66fe91
[/]
66fe91
handler = Root
66fe91
66fe91
[/secrets]
66fe91
handler = Secrets
66fe91
store = encrypted_sqlite