Re: Security of Private Key Recovery

From: Paul Adare - MVP - Microsoft Virtual PC (padare_at_newsguy.com)
Date: 07/28/04


Date: Wed, 28 Jul 2004 06:34:28 -0400

In article <eeDDN3IdEHA.712@TK2MSFTNGP09.phx.gbl>, in the
microsoft.public.windows.server.security news group, Christian Schindler
<christian.schindler@ntx.at> says...

> When I activate key archival for a windows server 2003 CA, the private keys
> are stored in the CA Database.
>
> The private key is generated on the client an than transfered to the CA,
> correct?
>
> I'm asking myself how the transfer of the private key to the CA is secured?
> Is the private key
> encrypted with the public key of the CA?
>

Full details on the process can be found in this white paper:

http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technolog
ies/security/kyacws03.mspx

or

http://tinyurl.com/6saoc

-- 
Paul Adare
This posting is provided "AS IS" with no warranties, and confers no
rights.


Relevant Pages

  • Re: Access token usb
    ... I issue thumbdrives to each user, each with an embedded private key, ... I encrypt the various sections of the database with a different ... control of a subscriber sharing decrypted information inappropriately. ... I need some one-way mechanism to load the fob with some ...
    (comp.lang.java.programmer)
  • Windows Regitry - Encryption Key storage
    ... We have a public and private key pair for Credit Card data encryption. ... The database part is all done where we generated the key pair. ... Problem is that when we use the "Multi-String" value in the registry to ...
    (microsoft.public.dotnet.general)
  • Re: Reinstall Enterprise CA server?
    ... If you do a backup of the database and private key using the certification ... options on install to preserve the existing database. ...
    (microsoft.public.windows.server.security)
  • Re: Windows Regitry - Encryption Key storage
    ... > We have a public and private key pair for Credit Card data encryption. ... > The database part is all done where we generated the key pair. ...
    (microsoft.public.dotnet.general)
  • Re: Security of Private Key Recovery
    ... > microsoft.public.windows.server.security news group, Christian Schindler ... >> are stored in the CA Database. ... >> The private key is generated on the client an than transfered to the CA, ...
    (microsoft.public.windows.server.security)