Re: handling asymmetric key that exists in a container

From: Anand Abhyankar [MS] (ananda_at_online.microsoft.com)
Date: 10/28/04

  • Next message: John Yang: "SCardEstablishContext on windows 2003 server"
    Date: Thu, 28 Oct 2004 13:05:52 -0700
    
    

    You can only have a max of 1 encryption key pair and 1 signing key pair in a
    container.

    -- 
    Thanks,
    Anand Abhyankar [MS]
    ----
    This posting is provided "AS IS" with no warranties, and confers no rights.
    "lelteto" <lelteto@discussions.microsoft.com> wrote in message 
    news:CDBA310F-417E-4D05-A4C2-FB17A182078A@microsoft.com...
    > The CSP shall always overwrite the old key with the new one. This is NOT 
    > an
    > error condition.
    >
    > Laszlo Elteto
    > SafeNet, Inc.
    >
    > "rayees@yahoo.com" wrote:
    >
    >> Hi,
    >>
    >> I have a question on how a custom CSP should handle an asymmetric key
    >> that exists in a container. The scenario is the following
    >>
    >> 1. generate an exchange key using CryptGenKey
    >> 2. encrypt some data with that exchange key
    >> 3. try to generate an exchange key using CryptGenKey again (same
    >> container) OR try to import a private key blob into the container.
    >>
    >> Should the CSP generate a new exchange key and move on OR should it
    >> return an error NTE_EXISTS?
    >> In the first case (generating new key), the old key is lost and the
    >> data encrypted is also lost.
    >>
    >> -rayees
    >>
    >> 
    

  • Next message: John Yang: "SCardEstablishContext on windows 2003 server"

    Relevant Pages

    • Re: encrypt a file?
      ... They have the advantage over gpg in that their contents are ... you are working with the container. ... Verify that using encryption is allowed your country, ... The instructions below refer to this script (and the associated ...
      (comp.os.linux.misc)
    • Re: Container within container (was Re: Whole OS encryption)
      ... container within an encrypted whole disk. ... for encryption within encryption (i.e., ... have his own Truecrypt container with overall OS protection ... protection while surfing if the Truecrypt containers are not ...
      (alt.computer.security)
    • Re: TrueCrypt Question
      ... Any encryption tool that stores passwords inside ... safe because inside the container that are encrypted. ... being saved start to overwrite the container space presuably the ...
      (alt.privacy)
    • Re: Thoughts on SafeBoot
      ... container encryption; the original post from Skulking Rogue just asked about ... referring to the total drive encryption product as opposed to the ... Anyway, when I said I could skip the / file encryption stuff in PGP, ...
      (alt.computer.security)
    • Re: Default Container for Smart Card based Certificate
      ... > Within ONE container you can have TWO ... the default container is used by Microsoft Certificate ... So we reserved this default container for key pair for Microsoft ... >> For Microsoft Certificate Logon, the Private Key is used for DECRYPT ...
      (microsoft.public.platformsdk.security)