cauliflowervest

App Engine-based escrow solution for enterprise management of disk encryption technologies for OS X (FileVault 2), Windows (BitLocker), and Linux (LUKS).

  • Owner: google/cauliflowervest
  • Platform:
  • License:: Apache License 2.0
  • Category::
  • Topic:
  • Like:
    0
      Compare:

Github stars Tracking Chart

ci

Overview

Note: OAUTH_CLIENT_ID moved from src/cauliflowervest/client/settings.py to
cauliflowervest/settings.py

Cauliflower Vest is a recovery key escrow solution.
The project initially started with end-to-end Mac OS X FileVault 2 support,
and later added support for BitLocker (Windows), LUKS (Linux), Duplicity, and
Firmware/BIOS passwords (Mac & Linux). The goal of this project is to streamline
cross-platform enterprise management of disk encryption technologies.

Cauliflower Vest offers the ability to:

  • Forcefully enable FileVault 2 encryption.
  • Automatically escrow recovery keys to a secure Google App Engine server.
  • Delegate secure access to recovery keys so that volumes may be unlocked or
    reverted.
  • Sync BitLocker recovery keys from Active Directory.

Components:

  • A Google App Engine based service which receives and securely escrows
    recovery keys.

  • A GUI client running on the OS X user machines, which enables
    FileVault 2 encryption, obtains the recovery key, and sends it to the escrow
    service.

  • A CLI tool which runs on Linux, for use with LUKS and Duplicity.

  • A script to sync BitLocker recovery keys from Active Directory.

Getting Started

Full source is available for all components.

To get started, begin with the Introduction
wiki page.

Warning

Upon releasing the update
to App Engine, start the schema update (/ui/#/admin/) otherwise
search and key retrieval will break. Progress can be
monitored in App Engine logs.
Logs will contain

UpdateSchema complete for VOLUME_TYPE with N updates!

for each volume type after successful migration.

Contact

Please search, join, and/or email the discussion list with questions at cauliflowervest-discuss@googlegroups.com.
To reach only engineers on the project, email
cauliflowervest-eng@googlegroups.com.

Thanks to Dorothy Marczak
for the logo.

Main metrics

Overview
Name With Ownergoogle/cauliflowervest
Primary LanguagePython
Program languagePython (Language Count: 5)
Platform
License:Apache License 2.0
所有者活动
Created At2014-10-16 20:04:13
Pushed At2021-01-15 16:58:14
Last Commit At2021-01-15 11:58:14
Release Count4
Last Release Name0.10.1 (Posted on )
First Release Name0.9.4 (Posted on )
用户参与
Stargazers Count278
Watchers Count29
Fork Count47
Commits Count164
Has Issues Enabled
Issues Count11
Issue Open Count4
Pull Requests Count3
Pull Requests Open Count2
Pull Requests Close Count3
项目设置
Has Wiki Enabled
Is Archived
Is Fork
Is Locked
Is Mirror
Is Private