Michael Stroeder:
> > Either way a compromised CA or a compromise KDC is bad news...
> 
> Yes!
> 
> And one of my biggest concerns are bad operational practices. That's why 
> admins should not have to manually deal with crypto key files like 
> service keytabs or TLS server keys.

To implement strong (network) security, some system will have to
keep some secret somewhere. Few people can afford operating an HSM
(hardware security module), what are the remaining options.

        Wietse

Reply via email to