Click here to get back home

Windows Key Manager

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Windows Key Manager SevDer 04-03-2006
---> Re: Windows Key Manager Roger Abell [MV...04-04-2006
Posted by SevDer on April 3, 2006, 2:53 pm
Please log in for more thread options
Hi,

I heard that Windows has a built in key manager that will be used for us to
securely store our keys that we use for our internal encryption rather that
hardcoding into the code or storing in text files.

Any suggestions for this purpose?

Thanks in advance.

--

SevDer
http://www.sevder.com
A new source for .NET Developers





Posted by Roger Abell [MVP] on April 4, 2006, 12:47 am
Please log in for more thread options
Perhaps you are meaning storage via the DPAPI (data protection api).
Check in MSDN


> Hi,
>
> I heard that Windows has a built in key manager that will be used for us
> to
> securely store our keys that we use for our internal encryption rather
> that
> hardcoding into the code or storing in text files.
>
> Any suggestions for this purpose?
>
> Thanks in advance.
>
> --
>
> SevDer
> http://www.sevder.com
> A new source for .NET Developers
>
>
>
>



Posted by SevDer on April 4, 2006, 10:06 am
Please log in for more thread options
No this is not the one because we are on web farm and thats why we need to
store our key somewhere.

--

SevDer
http://www.sevder.com
A new source for .NET Developers


> Perhaps you are meaning storage via the DPAPI (data protection api).
> Check in MSDN
>
>
>> Hi,
>>
>> I heard that Windows has a built in key manager that will be used for us
>> to
>> securely store our keys that we use for our internal encryption rather
>> that
>> hardcoding into the code or storing in text files.
>>
>> Any suggestions for this purpose?
>>
>> Thanks in advance.
>>
>> --
>>
>> SevDer
>> http://www.sevder.com
>> A new source for .NET Developers
>>
>>
>>
>>
>
>



Posted by Roger Abell [MVP] on April 4, 2006, 10:34 am
Please log in for more thread options
I am cross-posting to the iis.security newsgroup (even though you
have not state the web farm is IIS based).

I think I see why DPapi would not present a solution even though
storage in text file is, as indicated in initial post, a viable solution.

However, perhaps if you were to clarify your requirement and
the environment a little more.
Is this key just a string, or do you mean a certificate (that holds
this key)? I assume what you are after is safe storage of this key
that is used for your application internal encryption in such as way
that it will be automatically available upon automated provisioning
of a new server in the farm. Right? If so, characterize the farm
so we know what if any security contexts the instances share.

> No this is not the one because we are on web farm and thats why we need to
> store our key somewhere.
>
> --
>
> SevDer
> http://www.sevder.com
> A new source for .NET Developers
>
>
>> Perhaps you are meaning storage via the DPAPI (data protection api).
>> Check in MSDN
>>
>>
>>> Hi,
>>>
>>> I heard that Windows has a built in key manager that will be used for us
>>> to
>>> securely store our keys that we use for our internal encryption rather
>>> that
>>> hardcoding into the code or storing in text files.
>>>
>>> Any suggestions for this purpose?
>>>
>>> Thanks in advance.
>>>
>>> --
>>>
>>> SevDer
>>> http://www.sevder.com
>>> A new source for .NET Developers
>>>
>>>
>>>
>>>
>>
>>
>
>



Posted by SevDer on April 4, 2006, 12:27 pm
Please log in for more thread options
Hi,

Web farm is performed by hardware loadbalancer balanced over 4 web servers.
But our sites are hosted on IIS on each machine where all the servers have
the code on their own harddrives.

And yes, it is just a string key, but if you recommend we can put into
certificate (I don't know how).

I hope this information is enough.



--

SevDer
http://www.sevder.com
A new source for .NET Developers


>I am cross-posting to the iis.security newsgroup (even though you
> have not state the web farm is IIS based).
>
> I think I see why DPapi would not present a solution even though
> storage in text file is, as indicated in initial post, a viable solution.
>
> However, perhaps if you were to clarify your requirement and
> the environment a little more.
> Is this key just a string, or do you mean a certificate (that holds
> this key)? I assume what you are after is safe storage of this key
> that is used for your application internal encryption in such as way
> that it will be automatically available upon automated provisioning
> of a new server in the farm. Right? If so, characterize the farm
> so we know what if any security contexts the instances share.
>
>> No this is not the one because we are on web farm and thats why we need
>> to store our key somewhere.
>>
>> --
>>
>> SevDer
>> http://www.sevder.com
>> A new source for .NET Developers
>>
>>
>>> Perhaps you are meaning storage via the DPAPI (data protection api).
>>> Check in MSDN
>>>
>>>
>>>> Hi,
>>>>
>>>> I heard that Windows has a built in key manager that will be used for
>>>> us to
>>>> securely store our keys that we use for our internal encryption rather
>>>> that
>>>> hardcoding into the code or storing in text files.
>>>>
>>>> Any suggestions for this purpose?
>>>>
>>>> Thanks in advance.
>>>>
>>>> --
>>>>
>>>> SevDer
>>>> http://www.sevder.com
>>>> A new source for .NET Developers
>>>>
>>>>
>>>>
>>>>
>>>
>>>
>>
>>
>
>



Similar ThreadsPosted
Users tab in Task Manager on Windows 2003 November 10, 2005, 12:28 pm
Disable ALL Lan Manager Authentication September 20, 2005, 7:15 am
Service control manager May 16, 2007, 6:08 pm
Granting Rights to Processes in Task Manager May 3, 2006, 8:15 am
Re: Remote Access Connection Manager auto-starts (and can't be stopped) July 6, 2006, 4:17 pm
Allow power users to "Show Processes From All Users" in Task Manager May 25, 2007, 6:38 pm
Re: Windows Update Agent not found, or the computer is not running Windows 2000 SP3 or later. October 18, 2005, 4:15 pm
Windows 2000 Domain, Windows 2003 Enterprise CA July 15, 2005, 2:07 pm
Moving Standalone CA from Windows 2000, to Windows 2008? March 31, 2008, 10:05 am
Windows 2008 CA can't issue to Windows 2003 server June 25, 2008, 11:53 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap