News Focus
News Focus
icon url

SheldonLevine

06/15/06 3:58 PM

#123472 RE: awk #123438

awk, re: BitLocker/AD/KTM

1. I suppose that depends on how you define "key management". BitLocker can use AD to escrow SRKs, but that is only one key for disaster recovery. So if one accepts a definition of "key management" that includes keys other than the SRK, one could easily argue that your statement is correct.

2. Yes, that is correct. Although, KTM/KMS does not use AD as a data store for keys (as BitLocker does) - it uses AD for policy management and user authentication.

>>>
Active Directory — Embassy Key Management Server uses Active Directory for user authentication and policy management. Access control and authentication is achieved by role-based authentication and is integrated with Active Directory user authentication.
...
Policy-Driven — Embassy Key Management Server is policy-driven and designed to work with trusted platforms and enterprises having different security policies. The policy editor allows an administrator to set policies. Policies are administered through Active Directory and the server policies override client settings.
<<<
http://www.wave.com/products/ekms.html

Regards

SL