On 4/27/22 14:01, Wietse Venema wrote:
> Michael Stroeder:
>>> Either way a compromised CA or a compromise KDC is bad news...
>>
>> Yes!
>>
>> And one of my biggest concerns are bad operational practices. That's why 
>> admins should not have to manually deal with crypto key files like 
>> service keytabs or TLS server keys.
> 
> To implement strong (network) security, some system will have to
> keep some secret somewhere. Few people can afford operating an HSM
> (hardware security module), what are the remaining options.
> 
>       Wietse

TPM-backed storage might work, but I suspect it is too slow in
practice.  One could use TPM-based disk encryption though.

-- 
Sincerely,
Demi Marie Obenour (she/her/hers)

Attachment: OpenPGP_0xB288B55FFF9C22C1.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature
Description: OpenPGP digital signature

Reply via email to