Re: Storing Client Certificates
From: Eugene Mayevski (mayevski_at_eldos.org)
Date: 03/23/05
- Previous message: Todd Bright: "Re: Storing Client Certificates"
- In reply to: Todd Bright: "Re: Storing Client Certificates"
- Next in thread: Joe Kaplan \(MVP - ADSI\): "Re: Storing Client Certificates"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Wed, 23 Mar 2005 21:21:47 +0200
Hello!
You wrote on Wed, 23 Mar 2005 11:01:02 -0800:
TB> If someone hacked into the client machine and found the client cert
TB> they could send form posts and/or files over to our server. So I
TB> wanted to "hide" the client cert so noone but my app either knows where
TB> it is or can get to it.
You can store the certificate in encrypted form and let the user enter the
password. Of course, each user should have differently encrypted
certificate.
With best regards,
Eugene Mayevski
- Previous message: Todd Bright: "Re: Storing Client Certificates"
- In reply to: Todd Bright: "Re: Storing Client Certificates"
- Next in thread: Joe Kaplan \(MVP - ADSI\): "Re: Storing Client Certificates"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|