Re: How do I store secrets?

From: Danny van Kasteel (DannyvanKasteel_at_discussions.microsoft.com)
Date: 07/02/04


Date: Fri, 2 Jul 2004 08:15:03 -0700

Hmm, I'm not entirely sure how this would work in my case... Keep in mind that I need to verify that the CODE used to sign the message was my code. That means the certificate would have to reside INSIDE the code to make sure that it could not have been used by an imposter.

I suppose that the only way to ensure that a response is generated by "trusted" code, is to hard-code a private signing key into the dll, and use that to sign evidence which is sent to the server. The server can then use a public key stored in my database to verify that the right code has signed the evidence, since only my dll would know the private signing key?

This would mean that I only need to keep a close eye on my database to ensure (practically 100%) security.

Are these assumptions correct?

Danny van Kasteel

"Eugene Mayevski [SecureBlackbox]" wrote:

> Michel Gallant wrote:
>
> > If the certificate is issued (i.e. signed) by a KNOWN and TRUSTED CA, which
> > means that you implicitly trust the CA list provided by default by Microsoft (or Sun etc...)
> > to do due-diligence in issuing certs to parties, AND that you trust that the person who
> > was issued the cert him/her-self is using it in an appropriate way, then you trust the
> > authenticity of the signature.
>
> My idea was that the server issues and signs the certificates. Then the
> server trusts itself (to the extent it is protected from unauthorized
> access/modification).
>
> --
> Eugene Mayevski
> EldoS Corp., CTO
> Networking and security solutions, development and consulting services
> http://www.eldos.com
>
>



Relevant Pages

  • Re: setting a password on a button on the switchboard
    ... Could you send me the sample database for the fourth option (4. ... > Security in an Access database can probably be broken down into two big ... > points about being easier than User Level Security, ... > What type of data are you trying to protect? ...
    (microsoft.public.access.forms)
  • Re: access 2003
    ... security in access 2003. ... The data will go on the server and the program database ... than the alternative of creating an mde file. ... MDW file from the written record. ...
    (microsoft.public.access.conversion)
  • Re: access 2003
    ... security in access 2003. ... The data will go on the server and the program database ... than the alternative of creating an mde file. ... MDW file from the written record. ...
    (microsoft.public.access.conversion)
  • Re: Is this possible??
    ... I understand Windows security but since I've not seen A2007 live, ... The backend is on the server in it's own file. ... database, but everyone does not need to have access to tblwage which is ...
    (microsoft.public.access.tablesdbdesign)
  • Re: Is it safe to use social securty number as intranet username? (long)
    ... > they expect us to use our social security number as a username. ... by some database application ... ... The gateway router runs radius for authenticating ... ISPs perform internet connection authentication) ...
    (comp.security.firewalls)