Certificate Services database and key recovery security

From: Lars Olaussen (Isolauss_at_hotmail.com)
Date: 06/16/04


Date: Wed, 16 Jun 2004 10:25:53 +0200

As far as I know, the private keys are stored encrypted in the CA
database by using a random key with 3DES algorithm.

Is it possible to change this to 128/256 bit key size with AES
algorithm? If so, how?

And, I've seen that there are possibilites to delete entries in the CA
database; both single rows performed through certutil.exe and multiple
rows through eseutil.exe. I think I've read somewhere that the database
is hashed to know when changes has been performed, but I do not remember
the source.

Is it this feature that detects if one or more rows are deleted? If so,
is the whole database hashed as one? I also wonder if each database row
is signed by the CA when added, and if so, if they hashes are chained
together in any way.

Best regards,
Lars Olaussen
Isolauss@hotmail.com



Relevant Pages

  • Re: General Opinion on a how to?
    ... You could store the name of the algorithm in the database along with some ... Load into a prize pool object instance for that game ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: out of memory
    ... read only the smaller file into a hash. ... the smaller file will fit into RAM. ... Depending upon the sorting algorithm this would be Ologor ... put your relevant data into a database and use ...
    (comp.lang.perl.misc)
  • Re: out of memory
    ... the smaller file will fit into RAM. ... Depending upon the sorting algorithm this would be Ologor ... put your relevant data into a database and use ...
    (comp.lang.perl.misc)
  • Re: The crazy encryption madmans codebook
    ... Suppose database ranging 0-5 000 000 indexed word and phrases ... where each entry have an index, realworld word or phrase and a madman ... letters" when used off course you could use a hash algorithm that put ... discarding almost all of those resulting in an approximate entropy of 20-25 ...
    (sci.crypt)
  • Re: Who is a Good Programmer?
    ... >>optimum for speed and maintainability, ... There is an implication here about the choice of algorithm. ... get a database and don't try to write the code ... Chuck that clean, ...
    (comp.programming)

Quantcast