I have app which uses SSL cert to log in to server. Server is verifying client
certificate and checking it against custom CA (located on server). On the other
hand client is also veryfing server certificate and checks it with certificate
from custom CA, so there is full verification, and no errors during handshake.
But the problem is, that on client side cert and key are stored in application
private dir, which is inaccessible during normal phone usage, but when I
connect this phone to PC with USB in mass storage mode, private application
dir is accessible (at least I can see it) and probably someone would be able
to copy ssl key from phone, that in turn would compromise secure transmision,
right?
So finally the question: Is there some way to store this ssl key (file) in a
safer way on symbian device ? Has someone some idea/expierience with that ?
best regards
Marek
_______________________________________________
Interest mailing list
Inte...@qt-project.org
http://lists.qt-project.org/mailman/listinfo/interest
But that would require that you store the encryption key somewhere, possibly
in the application code. For an Open Source application, this makes no sense
of course. If it's closed, then you may be able to hide it, but not from a
skilled hacker.
I actually recommend storing the key in the platform's secure storage service.
--
Thiago Macieira - thiago.macieira (AT) intel.com
Software Architect - Intel Open Source Technology Center
Intel Sweden AB - Registration Number: 556189-6027
Knarrarnäsgatan 15, 164 40 Kista, Stockholm, Sweden