Welcome, Guest. Please login or register.
Did you miss your activation email?
June 19, 2013, 07:46:29 AM

Login with username, password and session length

668871 Posts
71127 Topics
145734 Members

Latest Member: vestwing8

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Business / Enterprise Security Products & Services
| |-+  Digital Certificates
| | |-+  Code Signing Certificate
| | | |-+  Certificates - Security and best practices
« previous next »
Pages: [1] Go Down Print
Author Topic: Certificates - Security and best practices  (Read 4724 times)
gchq
Newbie
*
Offline Offline

Posts: 8


Certificates - Security and best practices
« on: May 31, 2012, 01:10:26 PM »

We got our code signing certificate, exported it to a pfx file and browsed to the new file with VS2010. After entering the path to datestamp everything works (I hope) and we now have customers with a warm fuzzy feeling...

When the file was downloaded there was a warning about backing up the private key - does that mean just backup the certificate, or is there something else we should be doing to literally just backup the key?

With the Stuxnet issue flying around the internet it is quite clear that security is important - but can I find a step by step guide (other than the less than informative 'securing your private keys..' from Symantec) that runs through best practices? Does Comodo have such a guide? Clearly we don't want to compromise security, but we don't want VS2010 to kick off and throw all the toys out of the playpen when we deploy a clickonce project either.

If anyone can point me in the correct direction I would appreciate it!

Thanks
Logged
w-e-v
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 1092


BETA FORCE MEMBER


Re: Certificates - Security and best practices
« Reply #1 on: June 01, 2012, 03:13:51 PM »

Perhaps this KB article and this other one can help.
Logged
gchq
Newbie
*
Offline Offline

Posts: 8


Re: Certificates - Security and best practices
« Reply #2 on: June 01, 2012, 03:26:23 PM »

Hi w-e-v

Thanks for the reply

The first KB relates to W2K and XP (OS is Server 2008 R2) - and exporting to a pfx was not a problem.

The second KB refers to firefox - typical I guess that whilst you can navigate to the cert store within IE9 there are no backup functions, that I can see.. I see no reason that the daily server backup won't include the cert (which leads to other problems security-wise)

As it turns out this KB does go into backing up the cert - but it is the process for exporting the pfx. I guess it can be imported back into the certificate store from the pfx file. As it happens I exported two variants, one that included all certificates in the path and one that didn't (an issue with VS2010)...

More than anything I am trying to find a 'best practices' document to prevent the certificate becoming compromised...

Have a great weekend

« Last Edit: June 01, 2012, 03:40:26 PM by gchq » Logged
Tags: security 
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.061 seconds with 21 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com