EFS Private Keys Storage

From: Choi Wai Kin (choi4_at_i-cable.com)
Date: 02/28/04


Date: 27 Feb 2004 16:20:44 -0800

I am currently working on a new project using Oracle database to store
condifental information. My boss wants me to use EFS to encrypt the
data files. However, according to our department policy, the private
key used for encrypting condifental must be stored in a different
machine or in some kind of removable device (not in the database
server).

If I use a domain accout to encrypt the data files and then run all
Oracle services on the domain account, is it ture that the private key
will be stored in the domain controller instead of the local machine
and the private key will only be retrieved from the domain controller
when the Oracle services need to access the data file? And will the
private key be cached in the local harddisk?

BTW, is it possible to store the private key in a smart card? If so,
I wonder if there is any reference or white paper that I can refer to.

Thank you very much.

Regards,
Wai.

PS: I guess my boss does carry if the data is really secure, and he
only want to keep sure that we meet the department policy. :-)



Relevant Pages

  • Re: Encrypted data on webserver
    ... >> one of my customers demands realy high security. ... >> files (the HTML pages) on my webservers? ... > I expect you could probably encrypt data files with gpg/pgp in a cgi ...
    (comp.os.linux.security)
  • dbca fails to create db
    ... HPUX servers running 11.11 os ... Oracle 9iR2 installed successfully on both nodes. ... Data files for oracle using raw device. ... Trying to create the RAC database on the 2 servers using DBCA when I ...
    (comp.databases.oracle.server)
  • Re: Using EFS with SQL Databases
    ... Below are the steps encrypt the data files: ... Logon with the SQL Server startup account ... Right click the data files, select properties, click Advance button, ... database files are encrypted under the identity of the account ...
    (microsoft.public.sqlserver.security)
  • Re: Application transparent file encryption (supported)?
    ... data files in an application transparent manner; ... peecee utilities can encrypt an entire disk but apps running on the ... That is the disk controller does ...
    (comp.os.vms)
  • Re: MyLOG ready for test, an offline oracle log miner for 10g version.
    ... Both data files and log files are not belong to Oracle, ...
    (comp.databases.oracle.server)