Tutorial: Encrypted Email with Thunderbird and Enigmail. Author: Shashank Areguli. Published: Ed (August 9, 2014)



Similar documents
GPG4win / Kleopatra Documentation. Secure file and encryption by using GnuPG for Windows

GPG - GNU Privacy Guard

GPG installation and configuration

File and encryption with GPG4win & Enigmail

Encrypting with KMail, Mozilla Thunderbird, and Evolution LOCK AND KEY BY FRAUKE OSTER

An Introduction to Secure . Presented by: Addam Schroll IT Security & Privacy Analyst

Signing and Encryption with GnuPG

How to Setup Privacy Guard Encryption.

HW/Lab 1: Security with PGP, and Crypto CS 336/536: Computer Network Security DUE 09/28/2015 (11am)

THUNDERBIRD WORKBOOK

INTRODUCTION TO CRYPTOGRAPHY

Secure Part II Due Date: Sept 27 Points: 25 Points

The Handbook V 1.8 Adaptations by Ludwig Hügelschäfer Based on Version 1 by Daniele Raffo with Patrick Brunschwig and Robert J. Hansen.

GETTING STARTED SECURE FILE TRANSFER PROCEDURES A. Secure File Transfer Protocol (SFTP) Procedures

PGP from: Cryptography and Network Security

Pretty Good Privacy with GnuPG

How To Encrypt A Traveltrax Report On Gpg On A Pc Or Mac Or Mac (For A Free Download) On A Thumbdrive Or Ipad Or Ipa (For Free) On Pc Or Ipo (For An Ipo)

4. Click Next and then fill in your Name and address. Click Next again.

How to use PGP Encryption with iscribe

PDG Software. Encryption Guide

ENCRYPTION ENCRYPTION A BLACK PAPER HOW TO SECURE YOUR S FOR FREE WITH THE STRONGEST ENCRYPTION IN THE WORLD A BLACK PAPER

Signing and Encryption with GnuPG

Networks & Security Course. Web of Trust and Network Forensics

Using Your PGP Tool to Update Your Address Settings for Encrypted Messaging

Encrypting your Communications using PGP

LiteCommerce Advanced Security Module. Version 2.8

Ubuntu Open PGP IMPLEMENTATION. Dr. ENİS KARAARSLAN 2014

The KGpg Handbook. Jean-Baptiste Mardelle Rolf Eike Beer

Securing your Microsoft Internet Information Services (MS IIS) Web Server with a thawte Digital Certificate thawte thawte thawte thawte thawte 10.

Personal Secure Certificate

Biography of Trainer. Education. Experience. Summary. TLS/SSL : Securing your website PGP : Secure your communication. Topic

TABLE OF CONTENTS. Legend:

Encrypting Your Using the free COMODO Secure Certificate

gpg4o Manual Version 3.0

Receiving Secure from Citi For External Customers and Business Partners

PDG Software. PDG Key Manager User Guide

PDG Software. Keyman Encryption Guide

Methods available to GHP for out of band PUBLIC key distribution and verification.

Using PI to Exchange PGP Encrypted Files in a B2B Scenario

Personal Secure Certificate

How To Encrypt A Mail From Apa With A Keypress On Auntorom (For A Freebie) On A Pc Or Macbook Or Ipa (For Free) On An Ipa Or Ipam (For Cheap) On Your

Introduction to Cryptography

GPG Tutorial. 1 Introduction. 2 Creating a signing and encryption keys. 3 Generating a revocation certicate. Andreas Hirt July 12, 2009

Overview Keys. Overview

Setting Up Microsoft Outlook 2007 with GroupWise

SECURE USER GUIDE OUTLOOK 2000

Brocade Engineering. PKI Tutorial. Jim Kleinsteiber. February 6, Page 1

The Handbook by Daniele Raffo with Robert J. Hansen and Patrick Brunschwig v and earlier

Outlook Start Outlook, and click on mserver.wlu.ca. 2. From the Tools menu, choose Options

Trend Micro Incorporated reserves the right to make changes to this document and to the products described herein without notice.

1. Open the preferences screen by opening the Mail menu and selecting Preferences...

Pretty Good Privacy (PGP)

Published : License : None

PGP Desktop Quick Start Guide version 9.6

Why Johnny Can t Encrypt: A Usability Evaluation of PGP 5.0

Configuring Mozilla Thunderbird to Access Your SAS Account

PKI Contacts PKI for Fraunhofer Contacts

IMAP and SMTP Setup in Clients

Install and configure SSH server

IRMACS Setup. Your IRMACS is available internally by the IMAP protocol. The server settings used are:

Remember, this is not specific to your address alone... the METHOD you retrieve your is equally important.

User Guide. Version 3.0 April 2006

How To Configure Using Different Clients

CBH Provider EDI Browser Manual

HMRC Secure Electronic Transfer (SET)

Security. Friends and Enemies. Overview Plaintext Cryptography functions. Secret Key (DES) Symmetric Key

MANAGED FILE TRANSFER: 10 STEPS TO HIPAA/HITECH COMPLIANCE

User guide. Business

Microsoft Outlook 2007 to Mozilla Thunderbird and Novell Evolution Conversion Guide

Pretty Good Privacy PGP for Personal Privacy, Version 5.0. User s Guide. PGP, Inc. For the Mac OS

Using your Encrypted BlackBerry

PGP (Pretty Good Privacy) INTRODUCTION ZHONG ZHAO

Secure Frequently Asked Questions

1.2 Using the GPG Gen key Command

Address: Username: Password: password

MANAGED FILE TRANSFER: 10 STEPS TO PCI DSS COMPLIANCE

Client Configuration Secure Socket Layer. Information Technology Services 2010

Set up Outlook for your new student e mail with IMAP/POP3 settings

How to Setup your Account -Apple Mail for Mac OS X 1- Open Mail

CIPHERMAIL ENCRYPTION. CipherMail white paper

Encrypting and signing

6. Is it mandatory to have the digital certificate issued from NICCA? Is it mandatory for the sender and receiver to have a NIC id?...

Encryption. How do I send my encryption key?

1. Open the preferences screen by opening the Mail menu and selecting Preferences...

Exam Papers Encryption Project PGP Universal Server Trial Progress Report

Configuring Thunderbird for Flinders Mail at home.

Outlook Express. Make Changes in Red: Open up Outlook Express. From the Menu Bar. Tools to Accounts - Click on. User Information

Electronic Mail Security

CHARTER BUSINESS custom hosting faqs 2010 INTERNET. Q. How do I access my ? Q. How do I change or reset a password for an account?

HMRC Secure Electronic Transfer (SET)

PGP Desktop Quick Start Guide Version 10.2

Transcription:

Tutorial: Encrypted Email with Thunderbird and Enigmail Author: Shashank Areguli Published: Ed (August 9, 2014) There are three issues of security that needs to dealt with on the internet, concerning information. They are privacy, integrity and authentication. When you send a message to someone you want it to be private and you don't want it to be tampered with. Also, there needs to be a way to be certain of the identification of the sender or the receiver, to ensure authenticity of the message. Encrypting your message is the best way to keep your message private and maintain integrity; There are many encryption methodologies. One of them is a public key cryptography. When using a public key cryptography both parties have a pair of keys. One of them is a private key. And another one is a public key. The private key is kept secret and the public key is published so that everyone knows it. Messages encrypted by the public key can only be opened by the private key holder. Messages encrypted (known as signed) by a private key can be verified by the public key, ensuring authenticity. This method is widely used in electronic communication as PGP (Pretty Good Privacy). It's a encryption and decryption program for e-mail transmission and was released as a free program in 1991 by Phil Zimmermann. PGP uses a combination of methods along with public key cryptography. OpenPGP is the standard created by Internet Engineering Task Force for PGP and it is widely used. The GnuPG (GNU Privacy Guard) is another program that allows you to implement the PGP standard to encrypt and decrypt files and to be used in communication. Packages Required Enigmail is an extension for Mozilla Thunderbird email client and is used to encrypt, sign and verify your emails. It manages all the tasks for you using gnupg. gnupg is probably already installed by default on your system. If you are using a GNOME based distribution, the front-end Seahorse is probably also installed on your system. gnupg is a command-line program. There are also other graphical tools available other than Seahorse if you want to try an alternative. Seahorse is the Password and Keys package and can be found in System or Utilities categories in your application menu of choice. You can generate keys using any of them or you can do it while setting up Enigmail. To use Enigmail, only gnupg is required. You can download Thunderbird from their website or get it in your distribution's package manager. Installing Enigmail Since Enigmail is an extension you can just search for it in the add-on manager and install it. Or you

can download it on Enigmail's website. Enigmail is also available in repositories of both Ubuntu and Fedora. Now you have gnupg, Mozilla Thunderbird and Enigmail installed, you are ready. Enigmail Setup The Enigmail setup wizard is easy to set up and very descriptive. Simply go to Enigmail option in Thunderbird and start the Setup Wizard.

I do not want to encrypt all my emails so I am going to choose Auto Encryption option. It will auto-optimize the mail client to work with Enigmail. You can choose No if you want.

Here you get an option if you already have keys or have used gnupg or Seahorse to generate keys, you can choose them. I want to create a new pair of keys. Choose a Passphrase for your Private key. Based on the preferences, it is either managed by keyring or it will ask it every time you encrypt. You can change your Passphrase using key management option or in Password and Keys (Seahorse).

It will show you a summary of you preferences. Now do some work on your computer. Let it use environmental (digital) noise to generate pseudorandom numbers. Once you are done, it will ask you to export a key for revoking your private key, if you did choose to keep it secret.

You can manage keys in either any GnuPG front-end or directly inside Enigmail itself. You can publish it onto a key server to distribute your Public key. Now whenever you are writing a email, you will see the option to encrypt or sign at bottom right corner. By default, it will be as you configured in the wizard or preferences. You have to exchange your keys with others to send them encrypted mails and you have to import their keys to decrypt their mails, either via email or keyserver or any other media.

You can import keys from a file from the Key Management menu. When you receive an email Enigmail will decrypt and/or verify it for you. OpenPGP is a trusted standard and is widely used. Unless the private key is compromised it is technically impossible to read the message. Distributing the key using a key server is a good idea but it might give out information about you that you may not want public. Just a reminder, in case you wanted to keep it private.