Re: selfcert and new image or pc

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Word Heretic (myfullname_at_tpg.com.au)
Date: 01/22/05

  • Next message: gmaxey_at_mvps.org: "Re: Err object being reset and returning err.number = 0"
    Date: Sat, 22 Jan 2005 14:17:20 +1100
    
    

    G'day "prisma" <prisma@zonnet.nl>,

    No you cannot. Most certificates rely on unique numbers for that
    machine, including CPU serial numbers and OS install keys. So when you
    re-install the OS or buy a new computer, that certificate is no longer
    valid - I could be using a copy of your certificate to say I am you,
    and that is not on.

    So don't do it: you will hopelessly tangle up your security and
    potentially even lock yourself right out of office altogether.

    What can you do? Well, most professional development labs have a
    computer dedicated to code signing. Any old box suits for this
    purpose, strip its s/ware down to the minimum, only ever use to sign
    code, and you minimize your need for new certificates.

    Steve Hudson - Word Heretic

    steve from wordheretic.com (Email replies require payment)
    Without prejudice

    prisma reckoned:

    >Hello,
    >when I use selfcert to make a digital signature in an officedocument then
    >other users don't get a macrowarning (security medium). They have to trust
    >me as a good source. When I get a new computer my signature is lost and I
    >have to make a second signature. When I make other worddocuments with macros
    >after this the second signature has to be installed on the user-computer,
    >this is not the way I want it. I want to have one signature and I think it
    >is possible to export your signature as a *.cer file and load it on your new
    >computer after the new image. Is this possible or dangerous if you change
    >your hardware and if it is possible how is it done. I don't want to pay 400
    >dollar for an official signature a year.
    >Thanks a lot
    >
    >


  • Next message: gmaxey_at_mvps.org: "Re: Err object being reset and returning err.number = 0"

    Relevant Pages

    • Re: New Method for Authenticated Public Key Exchange without Digital Certificates
      ... > employing nicely handwritten contracts, ... certificates were redundant and superfluous when the relying party ... pre-existing business processes that have been around for a long time ... simple digital signature by itself isn't sufficient to be a legal ...
      (sci.crypt)
    • Re: selfcert and new image or pc
      ... G'day "prisma", ... including CPU serial numbers and OS install keys. ... and you minimize your need for new certificates. ... When I get a new computer my signature is lost and I ...
      (microsoft.public.office.developer.vba)
    • Re: Certificate attributes for Smart Card Logon
      ... signature but also email encryption! ... If you enable the Smart Card Logon, Client Authentication, and Secure ... controllers each already have their own certificates. ...
      (microsoft.public.windows.server.security)
    • Re: Digital verification of authentic documents ?
      ... The first one is a credit reference agency. ... signatures made with the issued certificates are legally ... binding under English law just like a physical signature. ... there are no organisations issuing legally valid PGP keys. ...
      (comp.security.misc)