Security Basics mailing list archives

Regarding Private key


From: manmeet Singh <mannirulz30 () yahoo com>
Date: Wed, 17 Jun 2009 02:38:42 -0700 (PDT)


Hi all,
I am facing a very tedious probelm. I want to know what the various options and how secure are these options.

I have a file that contains plaintext.I have to read that file and after first read , encrypt it(AES) and delete the 
plain text file and save the encryped file.On subsequent reboots, i have to read decrypted text.

Now the question is How do i manage the AES key?
Storing the AES key/IV in file is one option? (Isnt It same as storing the plain key assuming i dont have any secure 
storage)
Hard code  the AES Key/IV values  in the code?
What other options are possible. ?


Warm Regards,
Manmeet Singh




------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

Need to pass the CISSP? InfoSec Institute's CISSP Boot Camp in both Instructor-Led and Online formats is the most 
concentrated exam prep available. Comprehensive course materials and an expert instructor means you pass the exam. Gain 
a laser like insight into what is covered on the exam, with zero fluff!

http://www.infosecinstitute.com/courses/cissp_bootcamp_training.html
------------------------------------------------------------------------


Current thread: