> The adversary has root.  If the private key is encrypted, they must
> also break that passphrase to get the key.

But if an adversary gets root without rebooting your machine then the
unencrypted private keys are just sitting around in memory.  The 
passphrase is only protecting them between the time you reboot and the 
time you enter the passphrase.

Mark

______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl)                   www.modssl.org
User Support Mailing List                      [EMAIL PROTECTED]
Automated List Manager                            [EMAIL PROTECTED]

Reply via email to