Use chef-vault!
It uses the PKI that you already have through Chef Client's certificates and is way more flexible and easier to manage than encrypted data bags.
There's also a very detailed post by Joshua Timberman entitled Managing Secrets with Chef Vault.