I'm building a secrets manager as part of a web application. The idea is that multiple team members should be able to access various secrets (assuming correct application privileges). I'm using Laravel as my PHP framework. I'm a bit concerned about security and would appreciate any thoughts on the setup:
We accept a key/value pair (the key being a description of the secret, and the value being the secret itself) on the front-end which we then send to a function like this on the backend to save the 'value':
public function storeSecret(Request $request) {
...
$secret->value = Crypt::encryptString($request->secret);
$secret->save();
...
}
And to decrypt:
$decrypted = Crypt::decryptString($encryptedValue);
This is basically the exact example that the Laravel documentation has here: https://laravel.com/docs/8.x/encryption.
The documentation states that this uses AES-256 in Cipher Block Chaining mode, and that all of the encrypted values are signed with a Message Authentication Code.
The encryption/decryption key is being stored on each application server and they (the servers) are only accessible via key based authentication (where the only private keys are on my laptop and a USB backup).
Are there other security considerations that I should be thinking of here?