Re: secure storage of sensitive data in J2EE
[email protected] Tue, 25 Jan 2005 11:41:13 -0500
| Newsgroups | gmane.comp.security.programming,gmane.comp.security.web-applications |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 25 Jan 2005 09:18:15 GMT, chaim moshe said: > where can I store sensitive data like encryption keys, passwords, etc. in > J2EE? > surely, you can save it in the keystore, but the catch is where do you store > the keystore password to protect it from external access? > storing the keystore password in code or in config files is not secured > enough. So when you start up, you put up a dialog box and prompt for the password. This is hardly rocket science - Apache has had the *exact* same issue with starting an SSL-enabled webserver from day one. http://www.modssl.org/docs/2.8/ssl_reference.html#ToC2 http://www.modssl.org/docs/2.8/ssl_faq.html#startup http://www.modssl.org/docs/2.8/ssl_faq.html#remove-passphrase Same issues, even though it's OpenSSL rather than J2EE. You have to measure the tradeoffs of various security choices and take the route that sounds the best for your specific application. Basically, which worries you more - the cert being stealable if the machine is compromised, or the machine not restarting without human intervention in case of a problem?
signature.asc
(application/pgp-signature, 226 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.6 (GNU/Linux) Comment: Exmh version 2.5 07/13/2001 iD8DBQFB9napcC3lWbTT17ARAo4bAJ49NUjIQVeYmac4WT+469ZnzgeCjACfQiaY BIEQKMdOofrosJADnIu1TlI= =xGiN -----END PGP SIGNATURE-----