Re: Encrypt a UsernameToken Authenticated WSE Response



> key management does not require a cert.
> with or without a cert, you still have to manage the pub/pri keys.
> and most people cant manage their passwords.

Agreed. But if you sign your assem, you already have a public key at the
client and the server has the private key (or could have.) Naturally,
securing that private key requires special attention. But with a little
extra work, you can get much better security IMO.

> it depends on how secure you need to be,
> but i definitely think passwords (particularly pass phrases) have their
> place.

Agree. Thanks for discussion Casey.

--
William Stacey, MVP
http://mvp.support.microsoft.com


.



Relevant Pages

  • Re: Why couldnt Public keys replace Passwords on the Internet?
    ... First, I'd think you'd need a cert authority, which probably wouldn't be ... to do it carefully to store the private key securely. ... The browser could hold the users password which would ... Also no passwords would be passed across the internet. ...
    (microsoft.public.win2000.security)
  • Re: Why couldnt Public keys replace Passwords on the Internet?
    ... First, I'd think you'd need a cert authority, which probably wouldn't be ... to do it carefully to store the private key securely. ... The browser could hold the users password which would ... Also no passwords would be passed across the internet. ...
    (comp.os.ms-windows.nt.admin.security)
  • Re: Private & Public Key storage location
    ... with that you complete the 'certificate' to have both public and private key ... To view the complete cert, you access the cert mmc, ... its end & send only the public key to the CA along with the other websites ... The CA never know the private key of the website. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Private & Public Key storage location
    ... with that you complete the 'certificate' to have both public and private key ... To view the complete cert, you access the cert mmc, ... its end & send only the public key to the CA along with the other websites ... The CA never know the private key of the website. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Private & Public Key storage location
    ... When you got the server cert file, ... its end & send only the public key to the CA along with the other websites ... The CA never know the private key of the website. ...
    (microsoft.public.inetserver.iis.security)