Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 7087081
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 28, 20262026-05-28T07:37:47+00:00 2026-05-28T07:37:47+00:00

I would like to securely store a shared secret key on Windows but make

  • 0

I would like to securely store a shared secret key on Windows but make this key accessible by applications running under potentially different user accounts. On OSX, the solution is to put the key in the System Keychain with an appropriate ACL to restrict access to the key to only the various applications that require use of the key.

On Windows, secure storage (CryptProtectData() and CryptUnprotectData()) allows me to store the secret, encrypted for a particular user but does not seem to allow restricting access to the key to particular processes. Furthermore, there is no way using CryptProttectData to protect data for access by different users.

It seems my only option is a Windows Service that (1) stores the key data securely using CryptProtectData() and (2) exposes key data via a WCF endpoint, handling authentication/authorization in my service. This seems quite heavy (and error prone to get right). Is this my only option?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-28T07:37:48+00:00Added an answer on May 28, 2026 at 7:37 am

    Well…you can configure CryptProtectData() to encrypt so that data can be decrypted/accessed by different users by specifying the CRYPTPROTECT_LOCAL_MACHINE flag when you do the encrypt; this will allow any user account on the same computer to decrypt the data using CryptUnprotectData().

    As to specific-application(s) vs specific-users, there is not a straightforward way within Windows to do this. Windows’ security model is based on using user accounts to control access to resources, so you’re really left with this.

    I don’t know what usecases you have, but you could consider running the applications that need access to this data under one common user account (use the run-as capability) and then restrict access to the protected data to that one user account.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Would like to make anapplication in Java that will not automatically parse parameters used
I would like to implement OpenID on my website, but I would like to
I would like to securely transfer sensitive variables between multiple in PHP. Normally I
would like to set this convention up globally if possible.
would like to print a random number between 0 and 10, but generate seems
Would like to get a list of advantages and disadvantages of using Stored Procedures.
Would like to create a strong password in C++. Any suggestions? I assume it
Would like to be able to set colors of headings and such, different font
Would like to know what a programmer should know to become a good at
Would like to know the c# code to actually retrieve the IP type: Static

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.