5.17 Create specialized keychains for different purposes

Information

The keychain is a secure database store for passwords and certificates and is created for each user account on Mac OS X. The system software itself uses keychains for secure storage. Users can create more than one keychain to protect various passwords separately. If the user can logically split password and other entries into different keychains with different passwords, a compromise of one password will have limited effect.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Open Utilities Select Keychain Access Select File Select New Keychain Input name of new keychain next to Save As Select Create Drag and drop desired keychain items into new keychain from login keychain Impact: Using multiple keychains can be inconvenient. It is also not necessarily possible for all kinds of data, such as Safari auto-fill information, to be stored in secondary keychains. Not all keychain-aware applications may provide an interface to choose secondary keychains.

See Also

https://workbench.cisecurity.org/files/299