pgp_workshop
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| pgp_workshop [2025/05/29 07:36] – [Sign the public key of someone] usera | pgp_workshop [2026/07/16 12:37] (current) – [Signing and verifying signatures with OpenPGP] usera | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== PGP Workshop ====== | ====== PGP Workshop ====== | ||
| + | |||
| + | <aside outline box> | ||
| + | **Important note on PGP:** PGP has been more and more criticized in the security community over the years (see for example [[https:// | ||
| + | </ | ||
| Here is a small tutorial for getting started with this protocol named Pretty Good Privacy (PGP), an asymmetric cryptographic tool that allows to have end to end encrypted mails despite using very mainstream services like gmail, outlook, etc. You will find several names around, like GPG, PGP, OpenPGP. I will use them interchangeably as they basically refer to the same thing. | Here is a small tutorial for getting started with this protocol named Pretty Good Privacy (PGP), an asymmetric cryptographic tool that allows to have end to end encrypted mails despite using very mainstream services like gmail, outlook, etc. You will find several names around, like GPG, PGP, OpenPGP. I will use them interchangeably as they basically refer to the same thing. | ||
| Line 167: | Line 171: | ||
| The way it is done is the following: | The way it is done is the following: | ||
| - | - The file is **[[hashed|hashed]]** | + | - The file is **[[hashed|hashed]]**. |
| - This hashed file is encrypted with your private key | - This hashed file is encrypted with your private key | ||
| - The result is added at the end of your file, giving a **signed** file. | - The result is added at the end of your file, giving a **signed** file. | ||
| Line 284: | Line 288: | ||
| - Open a command line, navigate to the folder where your file is and enter '' | - Open a command line, navigate to the folder where your file is and enter '' | ||
| - repeat the operaton for each key you want to sign | - repeat the operaton for each key you want to sign | ||
| + | |||
| + | === The actual Key signing === | ||
| This is how to do it (as recommended [[https:// | This is how to do it (as recommended [[https:// | ||
| - Alice (you) get the public key of Bob | - Alice (you) get the public key of Bob | ||
| - | - Alice sign it with her private key: < | + | - Alice sign it with her private key: '' |
| - | - Alice exports, then encrypts the signed key with Bob public key, with the following command: < | + | - Alice exports, then encrypts the signed key with Bob public key, with the following command: < |
| - Alice emails the key to Bob using the mail address associated with the key | - Alice emails the key to Bob using the mail address associated with the key | ||
| - | - Bob receives it, then decrypt it with his private key and import it: < | + | - Bob receives it, then decrypt it with his private key and import it: '' |
| - | - He can then send it to a keyserver, containing Alice signature: | + | - He can then send it to a keyserver, containing Alice signature: |
pgp_workshop.1748504203.txt.gz · Last modified: by usera
