an-advanced-introduction-to-gnupg.pdf

(198 KB) Pobierz
An Advanced Introduction to GnuPG
Neal H. Walfield
neal@gnupg.org
RMLL, 6 July 2015
Outline
OpenPGP
GnuPG’s Architecture
Good Practices
Neat Tricks
OpenPGP
Data integrity service for messages and files
Defined in RFC 4880
Published in 2007
Focus
Message format
Message reading, writing and verification algorithms
Crypto algorithms to use and their parameters
Trade-offs
Good for data at rest
Need to be able to decrypt data in decades
OpenPGP is more like tar than http/smtp/xmpp
Consequence: Hard to phase out old algorithms
No interaction between encryptor and decryptor
Can’t negociate parameters dynamically
No perfect forward secrecy
Trade-offs
Good for data at rest
Need to be able to decrypt data in decades
OpenPGP is more like tar than http/smtp/xmpp
Consequence: Hard to phase out old algorithms
No interaction between encryptor and decryptor
Can’t negociate parameters dynamically
No perfect forward secrecy
Zgłoś jeśli naruszono regulamin