DISTRIBUTING REGISTRY INFORMATION IN A DISPERSED STORAGE NETWORK
A method begins by a processing module of a dispersed storage network (DSN) generating a signed registry information packet, dispersed storage error encoding the signed registry information packet to produce a set of encoded registry information slices, and generating a set of signed encoded registry information slice packets for storage in storage units of the DSN. The method continues with the processing module retrieving a decode threshold number of signed encoded registry information slice packets. For each of the decode threshold number of signed encoded registry information slice packets, the method continues with the processing module recovering an encoded registry information slice. The method continues with the processing module dispersed storage error decoding a decode threshold number of recovered encoded registry information slices to reproduce the signed registry information packet, validating the signed registry information packet, and extracting registry information when the signed registry information packet is valid.
1 . A method for execution by one or more processing modules of one or more computing devices of a dispersed storage network (DSN), the method comprises:
generating a signed registry information packet that includes:
registry information;
a certificate authority (CA) signed managing unit's certificate;
a registry information certificate; and
a CA signature for the signed registry information packet;
dispersed storage error encoding the signed registry information packet to produce a set of encoded registry information slices;
for an encoded registry information slice of the set of encoded registry information slices, generating a signed encoded registry information slice packet that includes:
the encoded registry information slice;
the CA signed managing unit's certificate;
an encoded registry information slice certificate; and
a CA signature for the signed encoded registry information slice packet; and
outputting the signed encoded registry information slice packet to a storage unit of the DSN.
2 . The method of claim 1 , wherein the registry information comprises one or more of:
hardware configuration information, software version information, software, software configuration information, user group affiliation information, an access control list, system namespace information, and vault information.
3 . The method of claim 1 , wherein the CA signed managing unit's certificate comprises:
an identifier of the CA;
an identifier of the managing unit; and
a public key of the CA.
4 . The method of claim 1 , wherein the registry information certificate comprises:
an identifier of the managing unit;
an identifier of the registry information; and
a public key of the managing unit.
5 . The method of claim 1 , wherein the encoded registry information slice certificate comprises:
an identifier of the managing unit;
an identifier of the encoded registry information slice; and
a public key of the managing unit.
6 . The method of claim 1 further comprises:
for each encoded registry information slice of the set of encoded registry information slices, generating a unique signed encoded registry information slice packet to produce a set of signed encoded registry information slice packets; and
outputting the set of signed encoded registry information slice packets to storage units of the DSN, wherein the set of signed encoded registry information slice packets includes the signed encoded registry information slice packet and the storage units includes the storage unit.
7 . A method for execution by one or more processing modules of one or more computing devices of a dispersed storage network (DSN), the method comprises:
receiving a signed certificate authority (CA) certificate;
retrieving at least a decode threshold number of signed encoded registry information slice packets of a set of signed encoded registry information slice packets;
for each of the at least a decode threshold number of signed encoded registry information slice packets, recovering an encoded registry information slice by:
validating a certificate authority (CA) signed managing unit's certificate of a signed encoded registry information slice packet based on the CA certificate to produce a valid managing unit's certificate; and
validating the signed encoded registry information slice packet based on the valid managing unit's certificate;
dispersed storage error decoding at least a decode threshold number of recovered encoded registry information slices to produce a signed registry information packet;
validating the signed registry information packet based on the valid managing unit's certificate by:
validating a second CA signed managing unit's certificate of the signed registry information packet based on the CA certificate to produce a second valid managing unit's certificate; and
validating the signed registry information packet based on the second valid managing unit's certificate; and
extracting registry information from the signed registry information packet when the signed registry information packet is valid.
8 . The method of claim 7 , wherein the signed registry information packet comprises:
registry information;
the second CA signed managing unit's certificate;
a registry information certificate; and
a CA signature for the signed registry information packet.
9 . The method of claim 8 , wherein the registry information comprises one or more of:
hardware configuration information, software version information, software, software configuration information, user group affiliation information, an access control list, system namespace information, and vault information.
10 . The method of claim 8 , wherein the second CA signed managing unit's certificate comprises:
an identifier of the CA;
an identifier of the managing unit; and
a public key of the CA.
11 . The method of claim 8 , wherein the registry information certificate comprises:
an identifier of the managing unit;
an identifier of the registry information; and
a public key of the managing unit.
12 . The method of claim 7 , wherein the signed encoded registry information slice packet comprises:
the encoded registry information slice;
the CA signed managing unit's certificate;
an encoded registry information slice certificate; and
a CA signature for the signed encoded registry information slice packet.
13 . The method of claim 12 , wherein the encoded registry information slice certificate comprises:
an identifier of the managing unit;
an identifier of the encoded registry information slice; and
a public key of the managing unit.
14 . A computer readable storage medium comprises:
at least one memory section that stores operational instructions that, when executed by one or more processing modules of one or more computing devices of a dispersed storage network (DSN), causes the one or more computing devices to:
generate a signed registry information packet that includes:
registry information;
a certificate authority (CA) signed managing unit's certificate;
a registry information certificate; and
a CA signature for the signed registry information packet;
dispersed storage error encode the signed registry information packet to produce a set of encoded registry information slices;
for an encoded registry information slice of the set of encoded registry information slices, generate a signed encoded registry information slice packet that includes:
the encoded registry information slice;
the CA signed managing unit's certificate;
an encoded registry information slice certificate; and
a CA signature for the signed encoded registry information slice packet; and
output the signed encoded registry information slice packet to a storage unit of the DSN.
15 . The computer readable storage medium of claim 14 , wherein the registry information comprises one or more of:
hardware configuration information, software version information, software, software configuration information, user group affiliation information, an access control list, system namespace information, and vault information.
16 . The computer readable storage medium of claim 14 , wherein the CA signed managing unit's certificate comprises:
an identifier of the CA;
an identifier of the managing unit; and
a public key of the CA.
17 . The computer readable storage medium of claim 14 , wherein the registry information certificate comprises:
an identifier of the managing unit;
an identifier of the registry information; and
a public key of the managing unit.
18 . The computer readable storage medium of claim 14 , wherein the encoded registry information slice certificate comprises:
an identifier of the managing unit;
an identifier of the encoded registry information slice; and
a public key of the managing unit.
19 . The computer readable storage medium of claim 14 further comprises:
the at least one memory section stores further operational instructions that, when executed by the one or more processing modules, causes the one or more computing devices of the DSN to:
for each encoded registry information slice of the set of encoded registry information slices, generate a unique signed encoded registry information slice packet to produce a set of signed encoded registry information slice packets; and
output the set of signed encoded registry information slice packets to storage units of the DSN, wherein the set of signed encoded registry information slice packets includes the signed encoded registry information slice packet and the storage units includes the storage unit.
20 . A computer readable storage medium comprises:
at least one memory section that stores operational instructions that, when executed by one or more processing modules of one or more computing devices of a dispersed storage network (DSN), causes the one or more computing devices to:
receive a signed certificate authority (CA) certificate;
retrieve at least a decode threshold number of signed encoded registry information slice packets of a set of signed encoded registry information slice packets;
for each of the at least a decode threshold number of signed encoded registry information slice packets, recover an encoded registry information slice by:
validating a certificate authority (CA) signed managing unit's certificate of a signed encoded registry information slice packet based on the CA certificate to produce a valid managing unit's certificate; and
validating the signed encoded registry information slice packet based on the valid managing unit's certificate;
dispersed storage error decode at least a decode threshold number of recovered encoded registry information slices to produce a signed registry information packet;
validate the signed registry information packet based on the valid managing unit's certificate by:
validating a second CA signed managing unit's certificate of the signed registry information packet based on the CA certificate to produce a second valid managing unit's certificate; and
validating the signed registry information packet based on the second valid managing unit's certificate; and
extract registry information from the signed registry information packet when the signed registry information packet is valid.
21 . The computer readable storage medium of claim 20 , wherein the signed registry information packet comprises:
registry information;
the second CA signed managing unit's certificate;
a registry information certificate; and
a CA signature for the signed registry information packet.
22 . The computer readable storage medium of claim 21 , wherein the registry information comprises one or more of:
hardware configuration information, software version information, software, software configuration information, user group affiliation information, an access control list, system namespace information, and vault information.
23 . The computer readable storage medium of claim 21 , wherein the second CA signed managing unit's certificate comprises:
an identifier of the CA;
an identifier of the managing unit; and
a public key of the CA.
24 . The computer readable storage medium of claim 21 , wherein the registry information certificate comprises:
an identifier of the managing unit;
an identifier of the registry information; and
a public key of the managing unit.
25 . The computer readable storage medium of claim 20 , wherein the signed encoded registry information slice packet comprises:
the encoded registry information slice;
the CA signed managing unit's certificate;
an encoded registry information slice certificate; and
a CA signature for the signed encoded registry information slice packet.
26 . The computer readable storage medium of claim 25 , wherein the encoded registry information slice certificate comprises:
an identifier of the managing unit;
an identifier of the encoded registry information slice; and
a public key of the managing unit.
27 . A computing device of a group of computing devices of a dispersed storage network (DSN), the computing device comprises:
an interface;
a local memory; and
a processing module operably coupled to the interface and the local memory, wherein the processing module functions to:
generate a signed registry information packet that includes:
registry information;
a certificate authority (CA) signed managing unit's certificate;
a registry information certificate; and
a CA signature for the signed registry information packet;
dispersed storage error encode the signed registry information packet to produce a set of encoded registry information slices;
for an encoded registry information slice of the set of encoded registry information slices, generate a signed encoded registry information slice packet that includes:
the encoded registry information slice;
the CA signed managing unit's certificate;
an encoded registry information slice certificate; and
a CA signature for the signed encoded registry information slice packet; and
output, via the interface, the signed encoded registry information slice packet to a storage unit of the DSN.
28 . The computing device of claim 27 , wherein the registry information comprises one or more of:
hardware configuration information, software version information, software, software configuration information, user group affiliation information, an access control list, system namespace information, and vault information.
29 . The computing device of claim 27 , wherein the CA signed managing unit's certificate comprises:
an identifier of the CA;
an identifier of the managing unit; and
a public key of the CA.
30 . The computing device of claim 27 , wherein the registry information certificate comprises:
an identifier of the managing unit;
an identifier of the registry information; and
a public key of the managing unit.
31 . The computing device of claim 27 , wherein the encoded registry information slice certificate comprises:
an identifier of the managing unit;
an identifier of the encoded registry information slice; and
a public key of the managing unit.
32 . The computing device of claim 27 , wherein the processing module further functions to:
for each encoded registry information slice of the set of encoded registry information slices, generate a unique signed encoded registry information slice packet to produce a set of signed encoded registry information slice packets; and
output, via the interface, the set of signed encoded registry information slice packets to storage units of the DSN, wherein the set of signed encoded registry information slice packets includes the signed encoded registry information slice packet and the storage units includes the storage unit.
33 . A computing device of a group of computing devices of a dispersed storage network (DSN), the computing device comprises:
an interface;
a local memory; and
a processing module operably coupled to the interface and the local memory, wherein the processing module functions to:
receive, via the interface, a signed certificate authority (CA) certificate;
retrieve, via the interface, at least a decode threshold number of signed encoded registry information slice packets of a set of signed encoded registry information slice packets;
for each of the at least a decode threshold number of signed encoded registry information slice packets, recover an encoded registry information slice by:
validating a certificate authority (CA) signed managing unit's certificate of a signed encoded registry information slice packet based on the CA certificate to produce a valid managing unit's certificate; and
validating the signed encoded registry information slice packet based on the valid managing unit's certificate;
dispersed storage error decode at least a decode threshold number of recovered encoded registry information slices to produce a signed registry information packet;
validate the signed registry information packet based on the valid managing unit's certificate by:
validating a second CA signed managing unit's certificate of the signed registry information packet based on the CA certificate to produce a second valid managing unit's certificate; and
validating the signed registry information packet based on the second valid managing unit's certificate; and
extract registry information from the signed registry information packet when the signed registry information packet is valid.
34 . The computing device of claim 33 , wherein the signed registry information packet comprises:
registry information;
the second CA signed managing unit's certificate;
a registry information certificate; and
a CA signature for the signed registry information packet.
35 . The computing device of claim 34 , wherein the registry information comprises one or more of:
hardware configuration information, software version information, software, software configuration information, user group affiliation information, an access control list, system namespace information, and vault information.
36 . The computing device of claim 34 , wherein the second CA signed managing unit's certificate comprises:
an identifier of the CA;
an identifier of the managing unit; and
a public key of the CA.
37 . The computing device of claim 34 , wherein the registry information certificate comprises:
an identifier of the managing unit;
an identifier of the registry information; and
a public key of the managing unit.
38 . The computing device of claim 33 , wherein the signed encoded registry information slice packet comprises:
the encoded registry information slice;
the CA signed managing unit's certificate;
an encoded registry information slice certificate; and
a CA signature for the signed encoded registry information slice packet.
39 . The computing device of claim 38 , wherein the encoded registry information slice certificate comprises:
an identifier of the managing unit;
an identifier of the encoded registry information slice; and
a public key of the managing unit.