> The adversary has root. If the private key is encrypted, they must > also break that passphrase to get the key.
But if an adversary gets root without rebooting your machine then the unencrypted private keys are just sitting around in memory. The passphrase is only protecting them between the time you reboot and the time you enter the passphrase. Mark ______________________________________________________________________ Apache Interface to OpenSSL (mod_ssl) www.modssl.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]
