Get a Pentest and security assessment of your IT network.

News

What is inadequate separation (segregation) of duties for PKIs?

Strong controls over the use of signing keys can enable the certification authority to be misused. This includes separating CA roles and setting policies so that the operation fails if an individual attempts to perform more than one CA role. A malicious actor might issue malicious certificates that allow a device or user to impersonate a legitimate user and conduct a man in the middle attack, or to digitally sign malware that is then propagated. It is preferable to implement a technology that enables a technical solution to the separation of duties policy.”]

Source: https://cpl.thalesgroup.com/faq/public-key-infrastructure-pki/what-inadequate-separation-segregation-duties-pkis

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2