PKI root signing ceremony, etc.
Arnold G. Reinhold
reinhold at world.std.com
Sun Dec 21 11:47:25 EST 2003
One approach to securing infrequent signing or working keys from a
corporate master certificate is to store the certificate in a bank
safe deposit box. The certificate generation software (say on a self
booting CD or perhaps an entire laptop) could be stored in the safe
deposit box as well. The certificate signing would take place at the
bank, either in one of the small rooms they provide or in a borrowed
conference room.
This approach buys a large amount of physical security and an audit
trail for the process at very minimal cost. It also addresses
another thorny problem: how to match the control of a corporate
master certificate to corporate governance mechanisms. Board members
of most corporations are poor potential custodians of cryptographic
material. Any password sharing system runs the risk of what to do if
the secret holders are all fired. Banks, on the other hand, are used
to dealing with situations like changing access controls after a
major management shakeup.
Arnold Reinhold
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com
More information about the cryptography
mailing list