Merge pull request #11765 from ldx/vault_pbkdf2hmac

Use PBKDF2HMAC() from cryptography for vault keys.
This commit is contained in:
Brian Coca 2015-08-21 11:06:00 -04:00
commit 144da7e7d1
2 changed files with 40 additions and 8 deletions

View file

@ -108,5 +108,11 @@ This is something you may wish to do if using Ansible from a continuous integrat
(The `--vault-password-file` option can also be used with the :ref:`ansible-pull` command if you wish, though this would require distributing the keys to your nodes, so understand the implications -- vault is more intended for push mode).
.. _speeding_up_vault:
Speeding Up Vault Operations
````````````````````````````
By default, Ansible uses PyCrypto to encrypt and decrypt vault files. If you have many encrypted files, decrypting them at startup may cause a perceptible delay. To speed this up, install the cryptography package::
pip install cryptography