Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 7517065
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 30, 20262026-05-30T01:19:44+00:00 2026-05-30T01:19:44+00:00

I am trying to figure out a solution to a ‘chicken and egg’ issue

  • 0

I am trying to figure out a solution to a ‘chicken and egg’ issue which I have come across in a project I am working on for a new venture.

The systems in question are handing credit card data and as such the card numbers etc need to be stored encrypted in the database. In order to comply with PCI requirements we have the numbers encrypted with unique key pairs for each ‘merchant’, so if one merchant is compromised it shouldn’t be possible to access another merchants card holder data.

This is fine when it comes to human interaction with the system, as the human can enter the passphrase to unlock the private key, and then decrypt the data, however when it comes to automated services which need to access the data (i.e. to process transactions at a later date) there is an issue with how best to provide the credentials to the service/daemon process.

A bit of background on the system:

  • card numbers are encrypted with asymmetric key pairs
  • the private key is passphrase protected
  • this passphrase is then encrypted with a ‘master’ key pair
  • the passphrase to unlock the master private key is then known by the operators granted permission (well, actually they a copy of it encrypted with their own key pair which they only know the passphrase to).
  • the daemon process will be run as its own user and group on a linux system.

For the daemon to be able to decrypt the data I was considering the following:

  • Setup a passphrase file similar to how .pgpass works
  • Store the file in the home directory for the daemon user
  • Set the permissions to 0600 for the file
  • Setup a file integrity monitoring system such as Tripwire to notify a security group (or similar) of any changes to the file or permissions.
  • Disable login for the daemon user, as it is used only for the process.

Given the above, I am wondering if this is sufficient. Obviously the weakness is with the system administrators – there are few of these (i.e. 2) trusted on the secure systems – given they can elevate their permissions (i.e. to root) and then change ownership on the files or the permissions to be able to read the passphrase – however once again this is likely something which can be mitigated with monitoring of checksum changes for files, FIM checksums etc.

So am I going about this the wrong way or are there other suggestions on how to handle this?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-30T01:19:46+00:00Added an answer on May 30, 2026 at 1:19 am

    Not sure how much help this will be as given your aim is compliance with PCI-DSS the person you need to convince is your QSA.

    Most QSA companies are happy to work in a consultative capacity and help you find a suitable solution rather than working purely in an assessment capacity so get them involved early and work with them to get a solution they are happy to sign off as compliant.

    It may be worth getting them to document why it is sufficient as well so that if you change QSA in the future you can take the reasoning with you in case the subject comes up again.

    One thing they are likely to mention based on the above solution is split knowledge for key management. It sounds like a single administrator has all the knowledge needed to access keys where PCI (3.6.6) requires split knowledge and dual control for manual clear-text key-management procedures.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I have been trying to figure out a solution but nothing has really presented
I have been trying to figure out a reliable solution in provide a drag-drop-upload
I'm trying to figure a solution out to the following. I have the following
I have been trying hard to figure out the best solution to a pagination
Trying to figure out which to use.
I'm trying to figure out a solution for a weird exception that raises at
I am trying to figure out how to create an optimal solution for my
Trying to figure out how to manage/use long-living DB connections. I have too little
I'm trying to figure out a transparent solution for debug halts that repeatedly get
I'm trying to figure out a decent solution (especially from the SEO side) for

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.