I have an S/MIME type of cert that is expiring in a month. I need to purchase a new one. Is there any type of certificate that KeePass will use to help secure my database? I use only Ubuntu Linux operating systems for secure access so any possible solutions need to work in my environment.
Also, is it possible to rename the KeePass program to help mitigate a malware attack from something like Citadel?
Thank you for your consideration,
James Finnall
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
I think I understood your suggestion. I created a new database and used my certificate file as the "key" during the creation process. It appears to create a database OK. I could edit, save, close and reopen. However, it never requested my pass phrase that is required. So it appears to have used the file as just random data.
Thank you for your time,
James
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
KeePass can use any file as a key file.
To be sure it is using the certificate as a key file, look at the details for the master key when you unlock the database.
How did you access the certificate under Linux?
Note: to be secure the certificate must not be available when you are not at the machine. I don't know if this is possible in Linux.
cheers, Paul
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
I have an S/MIME type of cert that is expiring in a month. I need to purchase a new one. Is there any type of certificate that KeePass will use to help secure my database? I use only Ubuntu Linux operating systems for secure access so any possible solutions need to work in my environment.
Also, is it possible to rename the KeePass program to help mitigate a malware attack from something like Citadel?
Thank you for your consideration,
James Finnall
There is a plug-in that uses certificates to secure the database. Look under Cryptography & Key Providers
You can rename KeePass to anything you like, but it won't prevent targetted malware stealing your data.
cheers, Paul
I see where there are three plugins for using certs. However, they are all Windows based. I am using Ubuntu Linux.
Thank you,
James
No option at persent, unless you use the certificate as a key file - can you even do this?
cheers, Paul
I think I understood your suggestion. I created a new database and used my certificate file as the "key" during the creation process. It appears to create a database OK. I could edit, save, close and reopen. However, it never requested my pass phrase that is required. So it appears to have used the file as just random data.
Thank you for your time,
James
KeePass can use any file as a key file.
To be sure it is using the certificate as a key file, look at the details for the master key when you unlock the database.
How did you access the certificate under Linux?
Note: to be secure the certificate must not be available when you are not at the machine. I don't know if this is possible in Linux.
cheers, Paul