So this is why you have all generated your keys and protected them with strong passphrases.
Recently there has been some discussion among the grid CAs as to whether the rules can be relaxed, without lowering the level of assurance too much. Many people generate their keys on systems which are maintained by someone else: e.g. your desktop at work, or maybe even a UI.
This leads to the proposed loosening of the rules, or perhaps a better description of existing practices.
It is likely that in the future, we will support private keys generated by:
- users themselves, on trusted systems (eg your own machine, or your desktop machine at work)
- institutions, letting them pre-generate keys for their users (apparently some like to do this);
- third parties: e.g. running a credential repository like MyProxy.
Anyway; the upshot of this is that private key protection rules will be relaxed. What is currently missing is the in-depth understanding of the security aspects of the lifecycle of the private key. I have soapboxed on this topic before. More on this later. Stay tuned.
No comments:
Post a Comment