Re: PKI (CA Hierarchy) and Hyper-V pros and cons



That does not protect the private keys.
Any body who is local Admin can:
1) Export the CA's private key and certificate
2) Import it into *any* computer they want
3) Issue a certificate that your org trusts and cannot revoke from the CA console
What type of business are you in. Are you sure that you are making the right decision.
But, to summarize, BitLocker does not replace a HSM
Brian

"hypnotix911" <hypnotix911@xxxxxxxxx> wrote in message news:O7XW9MAlIHA.5820@xxxxxxxxxxxxxxxxxxxxxxx
Thank you both,
but what about using bitlocker on VM files?
(we don't have a budget for HSM)




"hypnotix911" <hypnotix911@xxxxxxxxx> wrote in message news:OC9JVIqkIHA.4076@xxxxxxxxxxxxxxxxxxxxxxx
Enterprise three-tier CA hierarchy on virtual machines?
Or any part of hierarchy (offline or online CAs )? Is it bad idea?
Any thoughts?
Tnx a lot.




.



Relevant Pages

  • Re: CA, Certificates, some clearification
    ... No, the user certificate is stored on the AD user object, not the ... Private keys do not roam between machines for users unless you are using ... If the certificate is stored in> the user account, if the user moves between multiple machines, does he have> access to his public and private keys? ... > MMC on the server there is a pending request, why is it trying to create a> certificate for basic file encryption when i already have a certificate that> supports file encryption? ...
    (microsoft.public.win2000.security)
  • Re: E-mail encryption. Is this right? Isnt it a security hole?
    ... Regarding protecting your private keys, a good model is to never store your ... > When the receiver reads the encrypted e-mail uses his/her private key. ... > reads the CRL (Certificate Revocation List) from the Certificates CDP ...
    (microsoft.public.security)
  • Re: simple question about certificate chains
    ... Meant SSL of cource. ... The key to the whole certificate idea is keeping private keys private! ... You might be amazed at the effort that the certificate authorities such as ...
    (alt.computer.security)
  • Re: simple question about certificate chains
    ... Meant SSL of cource. ... The key to the whole certificate idea is keeping private keys private! ... You might be amazed at the effort that the certificate authorities such as ...
    (comp.security.ssh)
  • Re: P2P Authentication
    ... > use their private keys to encrypt data that they send to the other. ... resulting in the digital signature. ... appropriate public key (taken from the recipient's trusted public key ... this digital certificate is digitally ...
    (comp.security.misc)