RE: Key Management Utility



Dear Marc,
From your description, I understand that:
Your SQL Server 2005 is using data encryption by certificates. Due to your
company's policy the keys must be changed every 90 days, so you want to
know if a key management utility existed can help you on this process.
If I have misunderstood, please let me know.

If they want to use new certificate, you need to manually write script to
remove the old certificate and add the new one. Also, you need to get the
symmetric keys protected by certificates before they drop the old
certificate. There is no tool in SQL 2005 to do this automatically. You
can consider to create a job to run the script.

Also, you may use self-signed certificate which is not related to with
certificates issued by CA at all.

For more information, you can refer to:
http://www.microsoft.com/technet/itsolutions/msit/security/sqldatsec.mspx

Sincerely,
Charles Wang
Microsoft Online Community Support

======================================================
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from this issue.
======================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
======================================================



.



Relevant Pages

  • Re: RSA vs AES
    ... > Verisign, MS took the extra burden of issuing a critical patch to ... > those stolen root CAs. ... if any of these other keys ever got compromised ... ... BBN Certificate Services ...
    (sci.crypt)
  • Re: SSH vs. IKE trust models (was Re: Insecure IKE Implementations Clarification)
    ... >notebook, all the keys I need have already been stored, that's why I can ... Especially on university networks, you'll have to ... dsniff already handles the certificate case pretty well. ... >prohibitive ($200 per SSH server is a hefty price tag). ...
    (Bugtraq)
  • RE: [fw-wiz] insecurity in internet connection thro cable modems
    ... > - Sign the certificate with the local root CA created there ... > to function and create keys without needing a certificate, ... > where the PIX was 2 ... >> GlobalPro makes it easier to maintain a fleet of Netscreens. ...
    (Firewall-Wizards)
  • Re: EFS - how to force clients to use new certificate?
    ... As I know, if there is a CA available, the keys and certs are generated in ... which I believe uses the provider to generate the ... EFS will generate a self-signed cert. ... certificate and after the CA Certificate is issued, ...
    (microsoft.public.windows.server.sbs)
  • Re: Win2003 CA Cert Renewal
    ... >If you renew the CA certificate it will use the new key ... >multiple keys at the same time and will publish multiple ... >Windows Server 2003 PKI Operations Guide ...
    (microsoft.public.windows.server.general)