E2E crypto catch-22?

TonyB

ADSM.ORG Senior Member
Joined
Dec 10, 2009
Messages
383
Reaction score
9
Points
0
Location
Sydney, Australia
Hi,

I'm fairly sure this is a catch-22 but wanted to get verification...

The scenario is:

Client configured with serveronly session initiation plus encryptkey in save mode...

Server configured with serveronly session init for that client...

The catch-22 is:

The client cannot be used to prompt for and save a crypto key because its in serveronly init mode.

The server can initiate a session but that session can't prompt for a key...

The result is:

You have to use encryptkey in generate mode, which stores the crypto key at the TSM server and permits any buffoon (like me) that can use a grant command to read the encrypted data...


Does this sound about right?


Ty,

Tony
 
Back
Top