4 ms·
Certificates are public, they don't need protection. The private keys do. That said you always want to store a certificate close to its private key for practica
by nicolas314 11y ago
Certificates are public, they don't need protection. The private keys do. That said you always want to store a certificate close to its private key for practical reasons.
Smart cards are useful to transform your keys into a real object that is carried around and presented upon request. They offer the interesting property that they cannot be copied or used by illegitimate users, at least not without spending horrendous amounts of time and money. When your smart card is lost or stolen you can always revoke the credentials it contains on the server side and get new ones. Much harder to know when your browser key store was stolen from your computer.
- jdmichal 11y agoSo it's the transformation to a physical "thing you have" that is valuable? Would you say it is any better than a physical one-time code generator? Again, beyond the PITA argument; having used both I completely agree that the card was a lot easier.
- nicolas314 11y agoDefinitely that, and the fact they cannot be copied. OTP fobs offer the same convenience but are based on shared secrets that can be stolen from the server (happened to RSA). With PKI your private key is only on your smart card and nowhere else.