[Enigmail] Hello Enigmail, new user here!
Olav Seyfarth
olav at mozilla-enigmail.org
Mon Mar 10 13:26:31 PDT 2008
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi Dogssup,
Welcome abroad!
> Now, I don't know exactly what I'm doing
Well, read some howtos and manuals.
> I'm including my public key at the bottom
Perfect when contacting somebody for the first time. Even more perfect you
already put it on a public key server I noticed. So even somebody trying to
cantact you first will be able to encrypt to you.
> On peoples web pages they include their public key.
It's about telling people you use OpenPGP and about lowering probability of
a man-in-the-middle attack by providing seceral sources that you can compare.
> Do I copy and paste (import) this into Enigmail to start encryption
> correspondence?
Yes, or try to download it a public key server. While (re)importing, you'll
see a "unchanged" which verifies the key compare was OK.
> How do I know this public key has not been altered
Difficult.
> and/or the person I intend my encrypted mail to go?
Only possible by getting the receipient's fingerprint in a trusted way, e.g.
by handing it to you personally (and you checking his/her ID card ...).
> For this reason, I'd think putting the public key on a server is safer to
> avoid the risk of it being altered?
No. Why should you trust a public keyserver more that a public webserver not
to contain forged key(s). Play a bit with man-in-the-middle and you'll know.
> Sorry for all the questions!
No problem. But you may want to sebscribe to the PGP Basics group on Yahoo!
or the GnuPG users mailing list to discuss OpenPGP issues in more detail. On
this list, we focus on (directly) Enigmail related issues.
Olav
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (MingW32)
Comment: Diese ist eine Digitale Signatur nach OpenPGP-Standard
Comment: Weitere Informationen: http://privat.seyfarth.de/olav/
iJwEAQECAAYFAkfVmXQACgkQ/dJ0ek5GOmrKDQQAk5WhvnVv+kwXGAA4LMzNUx66
HgWUE4bYUmxhL4cjZynYyE4dlDNxs8Xez2MwCY+2crki0cbkeSnlxXCheZAxG3HN
QfJHGHKdtSth5xsLzyX+sNKAq5CtKySWtp60ddPamPBNuBMhgiaO4WoRObBC/JJs
gsvS5oW/dN0W/f6cMWo=
=8wd9
-----END PGP SIGNATURE-----
More information about the Enigmail
mailing list