Security question on using Laravel to create a secrets manager

Viewed 150

I'm building a secrets manager as part of a web application. The idea is that multiple team members should be able to access various secrets (assuming correct application privileges). I'm using Laravel as my PHP framework. I'm a bit concerned about security and would appreciate any thoughts on the setup:

We accept a key/value pair (the key being a description of the secret, and the value being the secret itself) on the front-end which we then send to a function like this on the backend to save the 'value':

public function storeSecret(Request $request) {
    ...
    $secret->value = Crypt::encryptString($request->secret);
    $secret->save();
    ...
}

And to decrypt:

$decrypted = Crypt::decryptString($encryptedValue);

This is basically the exact example that the Laravel documentation has here: https://laravel.com/docs/8.x/encryption.

The documentation states that this uses AES-256 in Cipher Block Chaining mode, and that all of the encrypted values are signed with a Message Authentication Code.

The encryption/decryption key is being stored on each application server and they (the servers) are only accessible via key based authentication (where the only private keys are on my laptop and a USB backup).

Are there other security considerations that I should be thinking of here?

0 Answers
Related