5 ms·
While I understand that Azure AD signing keys are used in a completely different context, would something like Certificate Transparency lower the impact of thi
by 1MachineElf 3y ago
While I understand that Azure AD signing keys are used in a completely different context, would something like Certificate Transparency lower the impact of this if it had been part of Azure AD architecture?
- mvandermeulen 3y agoUnfortunately not. Certificate Transparency in this case wouldn’t provide any real benefit. If your private key is compromised then any access the key provides is also compromised. The main problem here is that the key was able to be used outside of its intended scope and that MS don’t seem to have the systems in place to detect inappropriate key use in a proactive manner
- 1MachineElf 3y ago>MS don’t seem to have the systems in place to detect inappropriate key use in a proactive manner I'm sorry, I thought this was the point of CT... Although I guess it depends on how one defines "proactive" in this context.