This was a statement that I got from someone the other day: I wouldn’t use Windows as my offline root CA because it isn’t secure.
Err… blanket statements like that really irk me sometimes. While I can agree that Windows as an operating system tends to have some security problems (Microsoft is getting a little better at addressing these during design). In addition, those security problems may be cause for alarm if Windows is not deployed correctly. I would also have to state that all other operating systems also have their own form of security issues.
After all, its software that is written by humans and thus there will always be something that can be exploited to some degree. So, until Google’s AI project becomes self aware and starts pumping out code that will help manage all of humanities issues (oh wait that’s ViKi, scary). Then we need to learn how to deploy our systems using something that is called Defense in Depth (DID).
So, going back to the question, can you use Windows Server for your offline root CAs. Yes, you can, and you can even use it within a high assurance deployment. The catch is that you need to not only secure the operating system using the best means available to you. But, you must also put in multiple layers of controls that are designed to protect the assurance that is associated with that system. For example, if it’s an offline root, it should be kept offline except when performing a ceremony of some sorts. Or better yet, don’t keep the offline root with its key materials under your desk. Keep it within a secured room. Or hey… use a hardware security module (HSM) to protect the key materials. The list goes on…
In the end, making blanket statements helps know one. To truly understand if using something is a risk you need to understand the risk first. Then, only if the controls that you put into place do not mitigate the risk can you make a sound determination about the level of security associated with a piece of software, operation system, etc.
Hope this was helpful…
BTW – I really hate blog comment spam almost as much as email spam. Why!




