Management of code signing digital IDs and pvk files

Management of code signing digital IDs and pvk files

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Management of code signing digital IDs and pvk files Saqib Ali 05-05-2005
Posted by Saqib Ali on May 5, 2005, 6:04 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
This is a non-technical question:

I work in a group of 25+ developer, and we do NOT all report to same
management. We create executables, that we would like to digitally
sign. how can we manage digital ID and pvk file so that we don't have
a single point of failure, and still maintain the security of the pvk.

1) Should we give out the digital id + pvk pair to each developer? we
will be greatly reducing the security of the key this way.

2) Or should just one person be assigned the task of sign all
executables? This would be single point of failure.

3) Or a partial group (5 or 6) developer be given the pair? This seems
a happy medium.

Any ideas would be greatly appreciated.

Note: We all "need" to use the same Digital ID + pvk pair.

Thanks.
Saqib Ali
http://www.xml-dev.com/blog/


Similar ThreadsPosted
Need digital signatures for signing documents sent to clients August 12, 2004, 3:26 am
Re: Need digital signatures for signing documents sent to clients August 13, 2004, 5:15 am
Sony, Rootkits And Digital Rights Management Gone Too Far November 1, 2005, 10:08 pm
SSRT5958 rev.0 - HP OpenView Radia Management Portal (RMP) Radia Management Agent (RMA) Remote Unauthorized Privileged Access and Denial of Service (DoS) April 28, 2005, 6:33 pm
IT Risk Management June 20, 2004, 1:50 pm
risk management April 14, 2008, 7:37 am
Vulnerabilities Management System June 11, 2004, 4:50 am
Patch management factors January 29, 2005, 7:22 pm
Certificate Management Tools April 27, 2005, 9:35 am
Identity Management Best Practices July 14, 2006, 5:16 pm

The site map in XML format XML site map

Contact Us | Privacy Policy