Showing posts with label add-in. Show all posts
Showing posts with label add-in. Show all posts

Friday, January 10, 2020

Managing Public Keys in Encryptomatic OpenPGP for Outlook

Before any OpenPgp software can encrypt an email message, it needs to have access the recipient's public key.  

A public key allows anyone to encrypt a message to the recipient, but only the recipient can decrypt the message. A public key can be shared a number of different ways.

Sometimes the public key is attached as a file to an email message. 
Other times, the key may be uploaded to a public server that you can search.
If Encryptomatic OpenPGP can't find the recipient's public key in its local key store, it will ask your permission to search public key servers. 

Public key servers have worked fairly well for decades, but lately there has been problems with people spamming or "poisoning" the key server network to make it hard to discern the correct public key for certain people.  

Because anyone can upload a public key for any email address, and because some keys never expire (unexpired keys persist forever in the SKS key servers), this has started to become a problem.  Nevertheless, searching key servers is a good way to discover keys for many people, even while some high profile people are struggling with this spam.

How we help you manage public OpenPgp keys.


Given the present realities and limitations of the public key server network, we at Encryptomatic LLC advocate setting your keys to expire after a year or two. The expiration date can always be extended later, but try to avoid the problem of key accumulation that might confuse others as to which public key is the correct one.



Encryptomatic OpenPGP provides various capabilities around key management to help you.  From Settings > Key Management, you can import public keys several ways: from a text file,  from your Windows clipboard, or from the public key servers.

Image showing location of Key Management button in Microsoft Outlook.
Key Management Button in Microsoft Oulook

You can also share your public key by exporting it to a file, your clipboard, by attaching it directly to an email, or by uploading it to a public key server. You can work to keep your keys up to date by refreshing them from the public key server network.


Protecting your Private Key


While you can share your public key with anyone, make sure that protect your private key with a strong password.  Anyone who has your private key will be able to access any emails sent to you that were encrypted with your public key.  Keep the private key secure.




Wednesday, January 8, 2020

OpenPGP Email Encryption for Microsoft Outlook


Encryptomatic OpenPGP brings strong OpenPGP email encryption to Microsoft Office Outlook. It integrates tightly with the Microsoft Outlook 365/2019/2016/2013/2010 menu system, making it easy to encrypt and/or sign an email message.

From the Outlook main menu, you can  easily access Key Management features, as well as tweak how Encryptomatic OpenPGP works by adjusting the user options.
Screen shot showing Encryptomatic OpenPGP buttons in Outlook menu bar.
Encryptomatic OpenPGP in the Outlook main menu.

 To send an encrypted message from Outlook, first open a new email message.  Compose your message, then click the "Encrypt" and/or the "Sign" buttons in the message toolbar, and send.

Screen shot of a new email message in MS Outlook with Encrypt and Sign buttons activated.
Activate OpenPGP email encryption from any Outlook new email message.

Sending a message requires having the recipient's public key.  Encryptomatic OpenPGP uses the recipient's public key to encrypt the message. Sometimes you may want to send to someone whose public key has not yet been stored by Encryptomatic OpenPGP. If that happens, Encryptomatic OpenPGP will let you know, and will offer to check well known public key servers to locate the recipients key.  

An screen shot of "Keys not found." Click Yes to search public key servers.
Support is included for public OpenPGP key servers.

When the public key for the recipient is found, the email will be encrypted and sent, and a confirmation message will be displayed.

"Message has been Encrypted and sent successfully.
Encrypted message sent.
The recipient will receive a message in their email inbox that is unintelligible until it has been decrypted. It may look something like this:

An OpenPGP encrypted email message displayed in Microsoft Outlook 365.
Encrypted email message in inbox.
The recipient may use any OpenPGP compatible software and their private key to access the email message.  Usually, the private key is protected with a password.  Typically the way it works in email clients is that the recipient double clicks on the encrypted email message, types a password, and the email message is then displayed.

Screen image of a decrypted email message, showing text and a valid signature message.
Decrypted email message in Microsoft Outlook.
When Encryptomatic OpenPGP decrypts a message, it displays whether a valid signature has been detected.  A valid signature means that the message has not changed since the sender sent it.  "Valid Signature" only appears in messages where the sender has "Signed" the message.  Not all messages are signed. Unsigned messages display an "Invalid Signature" message. Why is this? Because Encryptomatic OpenPGP is unable to determine whether the message has been tampered with unless the message is signed. 

Note that it is possible to sign a message without encrypting it. Its also possible to encrypt a message without signing it.  The best practice is to both sign and encrypt a message.

Download Encryptomatic OpenPGP for Windows and MS Outlook, and start protecting your email messages today.

Download Encryptomatic OpenPGP
Requires Windows 10, MS Outlook 365/2019/2016/2013/2010