Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

DPAPI - Machine Specific keys

90 views
Skip to first unread message

Al

unread,
Jul 29, 2005, 12:50:42 PM7/29/05
to
Does anyone know what would cause the Machine-Specific key to change on a
machine? We would like to know so we can be prepared in case something
changes.

Thanks,

Al


John Banes

unread,
Jul 29, 2005, 4:09:51 PM7/29/05
to
A new DPAPI master key is automatically created every 90 days, and this new
key is used for all subsequent encrypt operations. The old keys are kept
around forever, though, so that you can continue to decrypt old data. I'm
not sure that this is what you're talking about, though.

In addition, DPAPI uses an LSA secret to protect machine master keys, which
are the master keys that get used when the CRYPTPROTECT_MACHINE flag is
passed into CryptProtectData. Apart from some special cases that happen
sometimes during setup, this LSA secret never changes as far as I know. Of
course, if you clean install Windows then you will end up with a new LSA
secret and so your old machine data will not decrypt.

Regards,
John


"Al" <n...@no.com> wrote in message
news:eRERq2Fl...@tk2msftngp13.phx.gbl...

al

unread,
Jul 29, 2005, 7:09:27 PM7/29/05
to

"John Banes" <jab...@comcast.remove.net> wrote in message
news:%23B7Y5lH...@TK2MSFTNGP15.phx.gbl...

al

unread,
Jul 29, 2005, 11:59:34 PM7/29/05
to
What we are trying to do is encrypt our sql connection strings for starters.
What we are concerned with is that if something changes such as the NIC card
will the system create a new key? Once this new key is generated will we
not be able to read our connection strings any longer? Also it is possible
for a machine to be moved from one domain to another. Will this action also
generate a new key?


Thanks,

Al

"John Banes" <jab...@comcast.remove.net> wrote in message

news:#B7Y5lHl...@TK2MSFTNGP15.phx.gbl...

David Cross [MS]

unread,
Aug 1, 2005, 8:14:19 AM8/1/05
to
No, none of those hardware changes will change the machine key or generate a
new one.

--
David B. Cross [MS]
--
This posting is provided "AS IS" with no warranties, and confers no rights.

"al" <x...@x.com> wrote in message
news:%23S8vTsL...@TK2MSFTNGP12.phx.gbl...

Al

unread,
Aug 1, 2005, 12:48:32 PM8/1/05
to
Thanks David and John for your responses.

Al

"David Cross [MS]" <dcr...@online.microsoft.com> wrote in message
news:uZKOKKpl...@TK2MSFTNGP12.phx.gbl...

0 new messages