Red Hat DIRECTORY SERVER 8.1 - 11-01-2010 Instrukcja Użytkownika

Przeglądaj online lub pobierz Instrukcja Użytkownika dla Serwery Red Hat DIRECTORY SERVER 8.1 - 11-01-2010. The Enigmail Handbook v1.0.0 Instrukcja obsługi

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
Przeglądanie stron 0
EnigMail
EnigMail
openpgp email security for mozilla applications
openpgp email security for mozilla applications
The Handbook
by Daniele Raffo
with Robert J. Hansen and Patrick Brunschwig
v 1.0.0 and earlier
Przeglądanie stron 0
1 2 3 4 5 6 ... 105 106

Podsumowanie treści

Strona 1 - EnigMail

EnigMailEnigMailopenpgp email security for mozilla applicationsopenpgp email security for mozilla applicationsThe Handbookby Daniele Raffowith Robert

Strona 2 - 1. Table of Contents

5. Getting startedThis chapter will illustrate how to get Enigmail up and running. To use Enigmail, you first need to install GnuPG. GnuPG comes in

Strona 3

Each letter of the passphrase is the first letter of each word. In the first line, the number is written in figures instead of being spelt out. In t

Strona 4

secret messages as you're typing them. For the purpose of recording, he might as well use a hardware keylogger installed between keyboard and ma

Strona 5 - 2. Introduction

It is also worth noting that a technically skilled intruder having physical access to a turned-off computer could infect it, leaving no traces, by rep

Strona 6

12.3.3. OpenPGP cardEnigmail supports the OpenPGP card, a smart cart compatible with ISO standards 7816-4 and 7816-8; see http://g10code.com/p-card.ht

Strona 7

clean Linux workstation not connected to any network and booted from a CD-ROM. The secret key is then moved to the card. Enigmail only supports on-c

Strona 8 - 3. Acknowledgements

/hexscd serialnoscd apdu 00 20 00 81 08 40 40 40 40 40 40 40 40scd apdu 00 20 00 81 08 40 40 40 40 40 40 40 40scd apdu 00 20 00 81 08 40 40 40 40 40 4

Strona 9 - 4. The Enigmail team

13. SupportThis handbook, once read in full, should answer all questions you might have about Enigmail and give you a thorough understanding of it. Y

Strona 10 - 5. Getting started

The first and most popular option is to use MacGPG. The MacGPG Project provides pre-built Universal Binaries of GnuPG 1.4.9 and later for users runni

Strona 11

You should have your mailclient and your email account fully configured before proceeding to the installation of Enigmail. 5.3. Installing EnigmailDo

Strona 12 - 5.3. Installing Enigmail

5.3.3. Installing a locale for EnigmailEnigmail is available in many languages. The following locales are already included in Enigmail 1.0.0: ar Arab

Strona 13

6. Quick startRun the email client you installed (Thunderbird or SeaMonkey). You will notice a new submenu called OpenPGP in the menu bar: that'

Strona 14 - 6. Quick start

6.1. The Setup WizardSelect OpenPGP → Setup Wizard and the following window will appear. Remember that you can abort the Setup Wizard at any time, and

Strona 15 - 6.1. The Setup Wizard

Here you can choose whether to have Enigmail configured to work on all your email accounts and identities, or for some only. If you are a beginner us

Strona 16 - Click Next

Here you can choose whether to sign all mail you send, or to pre-select recipients (through more complex per-recipient rules) to whom send signed mess

Strona 17

Here you can choose whether to enable encryption by default for all your outgoing mail. To encrypt a message, you need to have the public key of the

Strona 18

The Setup Wizard here asks you permission to modify some email settings to make sure Enigmail works seamlessly on your machine. You can safely select

Strona 19

1. Table of Contents2. Introduction...53. Acknowledgements...

Strona 20

Note that, as a good rule of netiquette, you should refrain from using HTML also when writing normal (unsigned, unencrypted) mail. The other setting

Strona 21

Perhaps you already used Enigmail (or GnuPG, or any other OpenPGP software) in the past before installing this version of Enigmail, and have created a

Strona 22

More likely, this is the first time you use OpenPGP, so you will need to generate a new key pair. Therefore, select I want to create a new key pair f

Strona 23

The last window of the Setup Wizard allows you to review the choices you've made and confirm. Click Next to commit the changes and finish. 23

Strona 24

Enigmail is now configured and ready to use.24

Strona 25

When you start writing a mail, you will now notice a new OpenPGP button in the toolbar of the Compose window. This button allows you to sign and/or e

Strona 26

When you receive a mail message that has been OpenPGP-secured (signed and/or encrypted), it will appear as such: The message in the figure has been b

Strona 27 - 7. Key management

7. Key managementOnce you have Enigmail on your system, you need to populate it with keys: it's pretty useless without them. You need to have yo

Strona 28

By clicking the expand gadget at the left of each key, you can see the key's additional user IDs and PhotoID, if present. The columns (Key ID, T

Strona 29

7.2. Generating your own key pairYou need to own a key pair to join the elite that communicates securely using GnuPG. You can create one at any momen

Strona 30 - 7.2.2. Choose a passphrase

8. Signature and encryption...428.1. Account settings...

Strona 31 - 7.2.5. Generate the key

7.2.2. Choose a passphraseYour private key is all that you need to send signed messages and decrypt messages that you receive on your selected email a

Strona 32

7.2.4. Choose the key type and sizeBy clicking the Advanced tab you can choose some properties used for the generation of your key pair: the Key size

Strona 33

You may also generate the revocation certificate at any later time by selecting your key pair and choosing Generate → Revocation certificate. 7.3. Ope

Strona 34

• Key validity and Owner trust indicate respectively the validity of the key and the trust in the key's owner. Key validity will show you whethe

Strona 35 - 7.3.6. Making a backup

The Add and Delete buttons add and delete other user IDs. An user ID is composed of a name and email address; it is also possible to put an optional

Strona 36

It is not currently possible to add a PhotoID from Enigmail, but you can do so from GnuPG command line. Assuming that 0x89ABCDEF is your key ID, type

Strona 37 - 7.5. Revoking your key pair

If you now click on Export Secret Keys, the exported file will contain your whole key pair (secret key and public key). If you click on Cancel instea

Strona 38 - 7.6. Importing public keys

7.4.2. Publish your public key on a keyserver By far, the easiest way to let the world know your public key is to publish it on the public keyserver n

Strona 39 - 7.7. Validity of public keys

→ Revoke key. This effectively creates a revocation certificate and imports it in one shot. Note that this command does not work in Enigmail 0.96.0

Strona 40 - 7.7.2. Trust levels

it to the clipboard (Ctrl+C under Windows). Then choose Edit → Import keys from Clipboard to import this public key into your keyring. You can search

Strona 41

Key Management window...9010.1.17. I get an error whenever I try to post to a n

Strona 42 - 8. Signature and

sign other people's keys to successfully use GnuPG or Enigmail. To participate, when you receive a public key and have verified both its fingerp

Strona 43

You can set the level of trust of a particular key by selecting that key and choosing the option Set Owner Trust from Key Management, or from Key Prop

Strona 44

8. Signature and encryptionYou have generated your own key pair and have imported other people's public keys, so you are now able to exchange sec

Strona 45 - 8.2.1. Signing a message

If you have multiple identities enabled, you can (and should) set these OpenPGP options independently for each identity. You will do this from the Id

Strona 46

• Send URL for key retrieval adds the mail header OpenPGP: url=url which mentions the URL from where your public key can be retrieved. If you enable

Strona 47 - 8.2.2. Verifying a signature

8.2. Signature and verification8.2.1. Signing a messageYou are now ready to write your first digitally signed email message.From your email client, cl

Strona 48

The following figure shows the composition of a signed message:Select the option Sign Message and click Send. The message will be signed with the key

Strona 49

8.2.2. Verifying a signatureNow, if your mailclient is set up so that a copy of outgoing emails is automatically saved in the Sent folder, it is possi

Strona 50

Now let's have a look at a signed message I received from [email protected], assuming I have his public key:The OpenPGP status bar tells that

Strona 51

What if I haven't had John Random Hacker's public key? In this case, the message would appear as such:The message is signed, but the signat

Strona 52

2. IntroductionThere are two main branches of cryptography: symmetric cryptography and asymmetric cryptography.Symmetric cryptography is the first typ

Strona 53 - 8.3.1. Encrypting a message

Finally, you might receive a mail that Enigmail shows as such: The signature is invalid, which means that the message has been altered in transit, or

Strona 54

Just click on Import and Enigmail will do that for you. The imported key will be added to your keyring. More often, you will receive someone's p

Strona 55

Adele's public key is now in my public keyring. 52

Strona 56

8.3. Encryption and decryptionHere comes the fun part – exchanging secret messages. 8.3.1. Encrypting a messageTo encrypt a message, select the option

Strona 57

Random Hacker's public key, as shown in the figure, and click Ok. The message would then be sent to [email protected] encrypted with John Ran

Strona 58

8.3.2. Decrypting an encrypted messageThis is a message that John Random Hacker sent encrypted to me:The status of the OpenPGP bar, the key in the hea

Strona 59 - 8.4. Handling attachments

HTKV+knUvwzBUkLCRWO6GaAjOBrV+t0RnJ3yAzEgo/UX+7+wZqnng/LIFUVLCcr8z/cN7CkLBVB2d/qyOXcU7gLq3/EdgHxIe8tqOwnYEugfqDtJp8oQtMUwXiw71X+d(... 18 lines omitted

Strona 60 - 8.5. Notes

I can use Adele's services to test that my messages are encrypted and decrypted correctly. As you remember, I have imported Adele's public

Strona 61 - 8.6. Per-recipient rules

A short time later, I receive Adele's reply:Notice that the OpenPGP status bar warns that the mail body is partly encrypted: Adele's message

Strona 62 - 8.6.2. Recipient Settings

8.4. Handling attachmentsWhen sending an encrypted or signed email message that has attachments, you will be given the choice how to encrypt/sign the

Strona 63 - 8.6.3. Notes

A digital signature is generated by an algorithm that uses a hash function in conjunction with a key. A hash function is a function that takes in inp

Strona 64

8.5. NotesMail headers cannot be encrypted, nor included in the signature computation. Do not write any sensitive information in the Subject when sen

Strona 65

8.6. Per-recipient rulesEnigmail features an advanced per-recipient rule editor that, for any recipient, allows you to specify in advance whether to s

Strona 66 - 9. Preferences

8.6.2. Recipient SettingsIn the Set OpenPGP Rules for field you must enter the recipient email address you're writing the rule for. Recipients a

Strona 67

to three options:• Never specifies that the function will be off.• Yes, if selected in Message Composition allows you to set the option at the time of

Strona 68

The rules are processed sequentially in the order displayed in the rules editor. If a rule contains an OpenPGP key, the rule is applied, but the addre

Strona 69 - 9.1.2. Sending

email defines the recipient address(es) to match. Multiple email addresses are separated by spaces. The matching is done on substrings, with curly b

Strona 70

9. PreferencesEnigmail can be fine-tuned to tailor your needs. This chapter illustrates the many configuration options of Enigmail.If you use GnuPG a

Strona 71 - 9.1.3. Key Selection

/usr/local/bin/gpg for Linux.If however Enigmail can't manage to find GnuPG, or you want to specify that location manually, tick Override with an

Strona 72 - 9.1.4. Advanced

In newer versions of Enigmail, the Display Expert Settings button activates instead the five tabs with the expert settings directly in the same window

Strona 73

9.1.2. SendingThese settings define how Enigmail must behave when sending secured mail. You can jump to this settings window also by selecting the men

Strona 74

GnuPG is free, open-source and available for several platforms. It is a command-line only tool, which means that it does not have a graphical interfa

Strona 75 - 9.1.5. Keyserver

Always confirm before sending prompts you a confirmation dialog before sending any message, so that you can check the signing, encryption, and S/MIME

Strona 76 - 9.1.6. Debugging

9.1.3. Key SelectionThis setting defines how Enigmail should select, for each recipient, the public keys to encrypt a message with. You can jump to t

Strona 77

9.1.4. AdvancedThese settings define miscellaneous OpenPGP and Enigmail options.Enable Encrypt replies to encrypted message if you want Enigmail to au

Strona 78

GnuPG version 2.0.x is distributed with gpg-agent. Enabling this option makes Enigmail use gpg-agent also for GnuPG version 1.4.x (this requires the

Strona 79

remember your choice for the future (for instance when choosing how Enigmail should sign/encrypt attachments), clicking this button will have Enigmail

Strona 80

9.1.5. KeyserverThese are the options related to keyservers used to search public keys from. The text field Specify your keyserver(s) allows you to sp

Strona 81

9.1.6. DebuggingThese options can help to track down why Enigmail doesn't work as expected.In the field Log directory you can type the name of a

Strona 82

9.2. Manually editing the preferencesManual editing of preferences are intended for advanced users only. Enigmail preferences are stored together wit

Strona 83

extensions.enigmail.agentPath ""The path to the GnuPG executable. If it is already in the PATH, this setting can be left blank. OpenPGP →

Strona 84

extensions.enigmail.confirmBeforeSend falsePops up the confirmation dialog before sending a message. OpenPGP → Preferences → Sending → Always confirm

Strona 85

3. AcknowledgementsThis Handbook stems from the Quick Start Guide written by Robert J. Hansen, and incorporates technical references written by Patric

Strona 86 - 10. Troubleshooting

extensions.enigmail.encryptAttachments 1This setting stores the value of the last encryption method used to send a message with attachment.extensions

Strona 87

extensions.enigmail.hushMailSupport falseEnables support for Hushmail. OpenPGP → Preferences → Advanced → Use '<' and '>'

Strona 88

extensions.enigmail.keyserver "pool.sks-keyservers.net, subkeys.pgp.net, pgp.mit.edu, ldap://certserver.pgp.com"The list of keyservers to u

Strona 89

extensions.enigmail.quotedPrintableWarn 0Issues a warning when Enigmail detects that a message going to be sent contains 8-bit characters and will us

Strona 90

extensions.enigmail.useGpgAgent falseUse gpg-agent to handle passphrases.OpenPGP → Preferences → Advanced → Use gpg-agent for passphrasesextensions.e

Strona 91

extensions.enigmail.wrapHtmlBeforeSend trueRe-wrap HTML text in signed messages before sending. Default is on.OpenPGP → Preferences → Sending → Re-w

Strona 92

10. TroubleshootingThis chapter contains several tips to troubleshoot any problem you may encounter when installing or using Enigmail.10.1.1. Thunderb

Strona 93

10.1.3. Enigmail fails to install on Firefox.Enigmail is an extension for Thunderbird and the SeaMonkey mailclient. It is not supposed to, and hence

Strona 94

Remember that Enigmail has only been tested with milestone releases of Thunderbird and SeaMonkey. If you use a nightly build, or your own build, Enig

Strona 95

10.1.11. I use a non-English character set, and my own signatures are invalid.When sending signed emails containing non-English characters (e.g. å or

Strona 96

4. The Enigmail teamPatrick Brunschwig Project Maintainer and Lead DeveloperRamalingam Saravanan (no longer active) Original author John Clizbe Qual

Strona 97

key, and hence your whole key pair is now useless.There is no way to recover your private key, either. It cannot be obtained from your public key or

Strona 98 - 12. Notes, Tips & Tricks

10.1.19. I get the message “OpenPGP error; Encryption/signing failed; send unencrypted message?”.This happen when you're writing a mail and you h

Strona 99

11. FAQThis chapter contains the Frequently Asked Question about Enigmail and around.11.1.1. Can Enigmail be used for webmail? When will this feature

Strona 100

11.1.4. Is it possible to use PGP with Enigmail?No. PGP is not supported with Enigmail. PGP does not provide a command line capability that Enigmail

Strona 101 - 12.2.2. Increased protection

following path: C:\Program Files\GNU\GnuPG\gpg.exe .(Depending on your localisation of Windows, your Program Files folder may be called Programmi, Pro

Strona 102 - 12.3.2. Encrypted volume

choices offer an excellent balance of speed, safety, and compatibility for the vast majority of users. Their opinions have evolved over time to take i

Strona 103 - 12.3.3. OpenPGP card

The matter is even worse when the email message is not stored on the local machine but on a POP/IMAP server instead. Not only this could potentially

Strona 104

11.1.15. How do I enable the debug log in Enigmail?Select OpenPGP → Preferences → Advanced → Debugging and type a valid directory path in the Log Dire

Strona 105

12. Notes, Tips & Tricks12.1. How to choose a good passphraseThe passphrase is the last line of defence to your private key, should your key pair

Strona 106 - 13. Support

Numerical constants e.g. 2.718281828459    (it's the mathematical constant e) Any of the above written in all uppercase, all lowercase, or with

Komentarze do niniejszej Instrukcji

Brak uwag