Subject: Policy-Discussion
List archive
- From: Dieter Hennig <dieter.hennig AT id.ethz.ch>
- To: "cacert-policy AT lists.cacert.org" <cacert-policy AT lists.cacert.org>
- Cc: Elwing <lraderman AT elwing.org>
- Subject: Re: Board inquisition of Multi-member escrow
- Date: Wed, 24 Mar 2010 00:59:30 +0100
Dear Laura,
sorry, I'm not an expert for using HSM-cards (right?) for a long time
(more then 20 years). My question is: how much it costs, to use it for
10 years, because after 10 yeares we would have to change the sub-roots
and in this case we could change the hardware too?
Elwing schrieb am 23.03.2010 13:32:
> As I saw this on the policy list, I'm replying there only.
>
> My first question is what mechanism is being used to store/generate the
> root keys? Is it an HSM (such as nCipher/SafeNet)? If so, why not use the
> multi-party mechanisms built into those HSMs? 5 key parts are generated on
> tokens (usually referred to as the "green" tokens) and distributed to 5
> people (board members perhaps?). At least 2 of those (up to 5 depending on
> the configuration) must be brought together to recreate the root key. At
> that point, you have legal recourse (at least in the US) with charges of
> collusion if the key parts are brought together without permission. The
> HSMs also provide for backup tokens if necessary.
> Since this is how the majority of CAs in the world handle this, I don't see
> how an auditor could fault you for doing something similar (I certainly
> wouldn't if I were auditing CACert).
>
> Now, I don't understand how the root key is being handled now, so this
> comment may be totally off.
>
> Laura
By my experience it is very hard to find SOC-cards, which are not broken
after 10 years. Hope, for the atom weapon missiles this is not the case,
but I'm not sure about.
Best regards
Dieter Hennig
--
Dieter Hennig
Informatikdienste/Helpdesk
ETH Zuerich, STB G 18.2
8092 Zuerich, Stampfenbachstr. 69
Tel: +41 44 632 4278
Fax: +41 44 632 1900
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature
- Board inquisition of Multi-member escrow, Daniel Black, 03/23/2010
- Re: Board inquisition of Multi-member escrow, Elwing, 03/23/2010
- HSM escrow - was: Re: Board inquisition of Multi-member escrow, Daniel Black, 03/23/2010
- Re: HSM escrow - was: Re: Board inquisition of Multi-member escrow, Mark Lipscombe, 03/24/2010
- Re: HSM escrow - was: Re: Board inquisition of Multi-member escrow, Ian G, 03/24/2010
- Re: HSM escrow - was: Re: Board inquisition of Multi-member escrow, Mark Lipscombe, 03/24/2010
- Re: Board inquisition of Multi-member escrow, Dieter Hennig, 03/23/2010
- Re: Board inquisition of Multi-member escrow, Lambert Hofstra, 03/24/2010
- Re: Board inquisition of Multi-member escrow, Elwing, 03/25/2010
- Re: Board inquisition of Multi-member escrow, Daniel Black, 03/25/2010
- Re: Board inquisition of Multi-member escrow, Ian G, 03/25/2010
- Re: Board inquisition of Multi-member escrow, Elwing, 03/25/2010
- HSM escrow - was: Re: Board inquisition of Multi-member escrow, Daniel Black, 03/23/2010
- Re: Board inquisition of Multi-member escrow, Ian G, 03/23/2010
- Re: Board inquisition of Multi-member escrow, Andreas Bürki, 03/24/2010
- Re: Board inquisition of Multi-member escrow, Mark Lipscombe, 03/24/2010
- Re: Board inquisition of Multi-member escrow, Daniel Black, 03/24/2010
- Re: Board inquisition of Multi-member escrow, Mark Lipscombe, 03/24/2010
- Re: Board inquisition of Multi-member escrow, Daniel Black, 03/24/2010
- Re: Board inquisition of Multi-member escrow, Mark Lipscombe, 03/24/2010
- Re: Board inquisition of Multi-member escrow, Daniel Black, 03/24/2010
- Re: Board inquisition of Multi-member escrow, Mark Lipscombe, 03/24/2010
- Re: Board inquisition of Multi-member escrow, Andreas Bürki, 03/24/2010
- Re: Board inquisition of Multi-member escrow, Elwing, 03/23/2010
Archive powered by MHonArc 2.6.16.