On 4/27/22 14:01, Wietse Venema wrote: > Michael Stroeder: >>> Either way a compromised CA or a compromise KDC is bad news... >> >> Yes! >> >> And one of my biggest concerns are bad operational practices. That's why >> admins should not have to manually deal with crypto key files like >> service keytabs or TLS server keys. > > To implement strong (network) security, some system will have to > keep some secret somewhere. Few people can afford operating an HSM > (hardware security module), what are the remaining options. > > Wietse
TPM-backed storage might work, but I suspect it is too slow in practice. One could use TPM-based disk encryption though. -- Sincerely, Demi Marie Obenour (she/her/hers)
OpenPGP_0xB288B55FFF9C22C1.asc
Description: OpenPGP public key
OpenPGP_signature
Description: OpenPGP digital signature
