<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; openpgp</title>
	<atom:link href="http://www.ghacks.net/tag/openpgp/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 24 Nov 2009 23:31:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Encrypt Thunderbird Email with Enigmail</title>
		<link>http://www.ghacks.net/2009/03/01/encrypt-thunderbird-email-with-enigmail/</link>
		<comments>http://www.ghacks.net/2009/03/01/encrypt-thunderbird-email-with-enigmail/#comments</comments>
		<pubDate>Sun, 01 Mar 2009 18:29:13 +0000</pubDate>
		<dc:creator>Jack Wallen</dc:creator>
				<category><![CDATA[Advice]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tutorials Basic]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[encrypting email]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[enigmail]]></category>
		<category><![CDATA[openpgp]]></category>
		<category><![CDATA[pgp]]></category>
		<category><![CDATA[thunderbird]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=10819</guid>
		<description><![CDATA[Sometimes email contains sensitive data which must be encrypted. You can handle this two ways, manually encrypt the data or use an exceptional Thunderbird Extension called Enigmail. This extension uses gpg and makes the encryption/decryption as user-friendly as it gets. With keys installed in Enigmail (either manually or from a keyserver) encrypted email is automatically [...]]]></description>
			<content:encoded><![CDATA[<p>Sometimes email contains sensitive data which must be encrypted. You can handle this two ways, manually encrypt the data or use an exceptional Thunderbird Extension called <a title="Enigmail" href="https://addons.mozilla.org/en-US/thunderbird/addon/71" target="_blank">Enigmail</a>. This extension uses gpg and makes the encryption/decryption as user-friendly as it gets. With keys installed in Enigmail (either manually or from a keyserver) encrypted email is automatically decrypted and signatures are checked for validity. This makes using encryption for email a task even the new user can master.</p>
<p>If you do not have a key pair generated, Enigmail can even do this for you. So with this extension you can encrypt/decrypt email without having to touch the command line. Pretty sweet. Let&#8217;s take a walk through this system.</p>
<p><span id="more-10819"></span></p>
<p>I am going to assume you know how to install an extension in Thunderbird (I am also going to assume gpg is installed). Knowing that, install the Enigmail extension. Once this extension is installed (and you have restarted Thunderbird), you will notice a new menu entry called OpenPGP. This is where you take care of the setup of Enigmail.</p>
<p><strong>Generate your key pair</strong></p>
<div id="attachment_10844" class="wp-caption alignleft" style="width: 310px"><a href="http://www.ghacks.net/wp-content/uploads/2009/03/enigmail_keymanage.png"><img class="size-medium wp-image-10844" src="http://www.ghacks.net/wp-content/uploads/2009/03/enigmail_keymanage-500x266.png" alt="Keymanager" width="300" height="160" /></a><p class="wp-caption-text">Keymanager</p></div>
<p>The first step is to generate your key pair. This can be done either from command line or from Enigmail itself. From within Thunderbird click the OpenPGP menu and click the Key Management entry to open the key manager window (shown in the image to the left.)</p>
<p>Click on the Generate menu and select New Key Pair to open the key generation window (shown below to the right.)</p>
<div id="attachment_10845" class="wp-caption alignright" style="width: 309px"><a href="http://www.ghacks.net/wp-content/uploads/2009/03/enigmail_genkey.png"><img class="size-medium wp-image-10845" src="http://www.ghacks.net/wp-content/uploads/2009/03/enigmail_genkey-499x411.png" alt="Keygen Window" width="299" height="247" /></a><p class="wp-caption-text">Keygen Window</p></div>
<p>From within this new window you have a number of options to consider (which are all fairly self explanatory.)For most instances the defaults will work. The only change you might make is if you do not want the key to expire click the Key Does Not Expire checkbox.</p>
<p>As the window says, during the generation process you will want to go about the business of using your PC in order to help randomize the process of key generation. This even holds true when you are generating keys via the command line in Linux.</p>
<p>If you already have a key on your machine (generated from the command line or some other tool) you can import that key from the same key manager tool shown above. Just click on the File menu and select <strong>Import Key from File</strong>.</p>
<p>Once your key has been imported into (or generated by) Enigmail you are ready to use Enigmail to encrypt your messages.</p>
<p><strong>Encrypt and Sign a Message</strong></p>
<p>Start composing a new email and you will notice the OpenPGP menu entry has been added. Once you have completed composing your email click on the OpenPGP menu and select Encrypt Message and/or Sign Message to encrypt and/or sign your outgoing messages with your key.</p>
<div id="attachment_10850" class="wp-caption alignleft" style="width: 307px"><a href="http://www.ghacks.net/wp-content/uploads/2009/03/enigmail_default_encryption.png"><img class="size-full wp-image-10850" src="http://www.ghacks.net/wp-content/uploads/2009/03/enigmail_default_encryption.png" alt="Default Encryption Options" width="297" height="298" /></a><p class="wp-caption-text">Default Encryption Options</p></div>
<p>This brings up an issue. If you do not configure Enigmail to not encrypt/sign by default all of your outgoing messages are going to be encrypted and signed. This is a problem when the recipient doesn&#8217;t have your key. I highly recommend configuring Enigmail to not encrypt/sign by default. To set this click on the OpenPGP menu entry in the MESSAGE COMPOSITION WINDOW (not the main Thunderbird window). From there click on the Default Composition Options sub menu and then select <strong>Signing/Encryption Options</strong>. A new window will appear (shown to the left.) Make sure you de-select all of the options in the Message Composition section. Now you have to manually choose to sign and encrypt each message. It&#8217;s one extra step but your non-geek friends and family will thank you for it.</p>
<p><strong>Decrypting</strong></p>
<p>Like send mail, you have two options for receiving mail. You can have encrypted mail automatically encrypted or you can do it manually. Of course for either options you have to have the senders&#8217; key imported into the system.</p>
<p>If you click on the OpenPGP menu (in the main Thunderbird menu) you will see an entry for <strong>Automatically Decrypt/Verify Messages</strong>. If this is checked all incoming encrypted/signed mail will be decrypted/verified. If it is not checked you will have to do this manually by selecting the encrypted/signed email and then clicking the <strong>Decrypt/Verify</strong>entry in the OpenPGP menu.</p>
<p><strong>Final Thoughts</strong></p>
<p>And that&#8217;s it! Simple email encryption in Linux with Thunderbird and Enigmail. You can, of course, do this manually from the command line, but why make things difficult? If you have needs to encrypt/sign outgoing or incoming email, Enigmail is the perfect solution for every Linux and Thunderbird user. And for those BSD, Solaris, OS/2, Mac, or Windows users there is an Enigmail for you as well.</p>

	Tags: <a href="http://www.ghacks.net/tag/encrypting-email/" title="encrypting email" rel="tag">encrypting email</a>, <a href="http://www.ghacks.net/tag/encryption/" title="encryption" rel="tag">encryption</a>, <a href="http://www.ghacks.net/tag/enigmail/" title="enigmail" rel="tag">enigmail</a>, <a href="http://www.ghacks.net/tag/linux/" title="Linux" rel="tag">Linux</a>, <a href="http://www.ghacks.net/tag/openpgp/" title="openpgp" rel="tag">openpgp</a>, <a href="http://www.ghacks.net/tag/pgp/" title="pgp" rel="tag">pgp</a>, <a href="http://www.ghacks.net/tag/thunderbird/" title="thunderbird" rel="tag">thunderbird</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/10/15/secure-your-files-an-introduction-to-gnupg/" title="Secure your files: An introduction to GnuPG (October 15, 2008)">Secure your files: An introduction to GnuPG</a> (4)</li>
	<li><a href="http://www.ghacks.net/2009/06/03/recursively-encrypt-directories-with-gpgdir/" title="Recursively encrypt directories with gpgdir (June 3, 2009)">Recursively encrypt directories with gpgdir</a> (3)</li>
	<li><a href="http://www.ghacks.net/2005/11/15/cryptography-tutorial/" title="Cryptography Tutorial (November 15, 2005)">Cryptography Tutorial</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/02/07/yoggie-pico-personal-mobile-security-computer/" title="Yoggie PICO Personal Mobile Security Computer (February 7, 2008)">Yoggie PICO Personal Mobile Security Computer</a> (3)</li>
	<li><a href="http://www.ghacks.net/2009/10/30/with-ubuntu-9-10-arrives-wubi-9-10/" title="With Ubuntu 9.10 Arrives Wubi 9.10 (October 30, 2009)">With Ubuntu 9.10 Arrives Wubi 9.10</a> (2)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/03/01/encrypt-thunderbird-email-with-enigmail/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Secure your files: An introduction to GnuPG</title>
		<link>http://www.ghacks.net/2008/10/15/secure-your-files-an-introduction-to-gnupg/</link>
		<comments>http://www.ghacks.net/2008/10/15/secure-your-files-an-introduction-to-gnupg/#comments</comments>
		<pubDate>Wed, 15 Oct 2008 20:51:31 +0000</pubDate>
		<dc:creator>Joe</dc:creator>
				<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Tutorials Basic]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[gpg]]></category>
		<category><![CDATA[openpgp]]></category>
		<category><![CDATA[pgp]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=7650</guid>
		<description><![CDATA[GnuPG allows you to encrypt data so only the intended recipient, with a key and a password, can decrypt it. It also provides a mechanism for verifying data is from the person who has claimed to send it. GnuPG can also provide a way for you to securely prevent your files from being opened without [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.gnupg.org/">GnuPG</a> allows you to encrypt data so only the intended recipient, with a key and a password, can decrypt it. It also provides a mechanism for verifying data is from the person who has claimed to send it. GnuPG can also provide a way for you to securely prevent your files from being opened without authorisation (<a href="http://en.wikipedia.org/wiki/United_States_v._Boucher">at a US border, for example</a>).</p>
<p>GnuPG, in technical terms, utilises a mixture of symmetric-key cryptography and public-key cryptography. This basically means a person generates a pair of keys; one of which is publicly shared and one is not. The publicly shared key is used to people can encrypt data for a specific person whilst the private key is used to decrypt, encrypt and sign data.</p>
<p>If you encrypt data to only be decrypted only by your private key and you carry your private key on another medium of storage, the data you encrypted will be effectively impossible to decipher.</p>
<p>To get started with GnuPG, <a href="http://www.gnupg.org/download/index.en.html">you must download GnuPG</a> which is free and open-source.</p>
<p><span id="more-7650"></span>GnuPG is available for effectively all operating systems. After you have downloaded and installed GnuPG, it might be wise to download a graphical interface because it is command line based.</p>
<p>Some GUIs focus on the management of keys, such as the generation of them and storing other people&#8217;s public keys, whilst others focus on the encrypting/decrypting.</p>
<p>WinPT is a popular Windows option. As for encrypting and decrypting, there are many choices including Enigmail for Thunderbird, FireGPG for Firefox and WinPT also provides facilities to do this.</p>
<p>With a GUI, it is fairly easy to get to grips with GnuPG. Most key managers provide wizards for the generation of keys.</p>
<p>To obtain someone&#8217;s public key, so you can send data to them securely, you could either ask them or go onto a keyserver such as pgp.mit.edu, copy their key into Notepad and then import it into your key manager.</p>
<p>It is essential to send your keys to keyservers, I would suggest pgp.mit.edu, and this can be done either through the GUI or through exporting your public key and uploading it to these sites. Once you have someone&#8217;s public key, and you are sure it belongs to them and is not a hoax, you can sign the key inside your key manager and then submit it, so people know that key is authentic.</p>
<p><strong>Key software to get started with GPG</strong></p>
<ol>
<li><a href="http://www.gnupg.org/">GnuPG</a> is absolutely necessary. <a href="ftp://ftp.gnupg.org/gcrypt/binary/gnupg-w32cli-1.4.9.exe">There is a Windows binary available.<br />
</a></li>
<li>A GUI is also necessary. For Windows users, WinPT is a safe bet.</li>
<li>If you use Thunderbird, install <a href="http://enigmail.mozdev.org/home/index.php">Enigmail</a>. If you use Firefox, install FireGPG.</li>
</ol>
<p>If you have installed GPG and would like to try it out, feel free to send me an encrypted email. My email is computerjoe (at) gmail.com and my key is on this page.</p>

	Tags: <a href="http://www.ghacks.net/tag/encryption/" title="encryption" rel="tag">encryption</a>, <a href="http://www.ghacks.net/tag/gpg/" title="gpg" rel="tag">gpg</a>, <a href="http://www.ghacks.net/tag/openpgp/" title="openpgp" rel="tag">openpgp</a>, <a href="http://www.ghacks.net/tag/pgp/" title="pgp" rel="tag">pgp</a>, <a href="http://www.ghacks.net/tag/security/" title="Security" rel="tag">Security</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/03/01/encrypt-thunderbird-email-with-enigmail/" title="Encrypt Thunderbird Email with Enigmail (March 1, 2009)">Encrypt Thunderbird Email with Enigmail</a> (7)</li>
	<li><a href="http://www.ghacks.net/2005/11/15/cryptography-tutorial/" title="Cryptography Tutorial (November 15, 2005)">Cryptography Tutorial</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/07/07/true-crypt-6-released/" title="True Crypt 6 released (July 7, 2008)">True Crypt 6 released</a> (3)</li>
	<li><a href="http://www.ghacks.net/2005/12/11/securing-your-pc-with-true-crypt/" title="Securing your Pc with True Crypt (December 11, 2005)">Securing your Pc with True Crypt</a> (29)</li>
	<li><a href="http://www.ghacks.net/2009/06/03/recursively-encrypt-directories-with-gpgdir/" title="Recursively encrypt directories with gpgdir (June 3, 2009)">Recursively encrypt directories with gpgdir</a> (3)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/10/15/secure-your-files-an-introduction-to-gnupg/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
