Notes about PGP

"Suggesting a security policy for PGP clients" - Application Note, November 1999 Doc 760 kb. ZIP:ed 360 kb
A step by step guide based upon practical experience of implementing PGP's security policy within corporations. With extensive screenshots and comments, it suggests guidelines for "best practices". It also explains the motives behind certain choices that an administrator encounters during the creation of a customised PGP client. The text is a part in the knowledge exchange within NAI's PGP International Technical Group, but can also be used by administrators with prior knowledge of PGP, or in courses for implementing PGP's PKI solution.

Comparing PGP/MIME and S/MIME

"The Caligula virus and its impact on PGP"
It grabs PGP’s private keyring, and sends it to an ftp site.If your passphrase is cracked, your identity can be used or revoked by the attacker, and all encrypted messages can be read. Presentation on EICAR''s conferens '99. European Institute for Computer Antivirus Research. Their website
http://www.eicar.org/wg_infosec/index.html has the 19 PowerPoint slides and references. Latest change, March- 99.

Setting up a dedicated PGP certification server A step by step guide for ver 1.0.2

How and why PGP should be integrated with smart card

The differences between PGP 6.0.2 versions. Business, Personal, US-Freeware and International-Freeware

Files used by version 6.0 and 5.0

Details Inside PGP 5

FAQ on PGP, tilted towards ver 5 and later

"Corporate use of PGP & Key management /recovery" is a paper that was presented at Nordsec'98, a Nordic Security Conference in Norway, 6-7 November -98, http://www.item.ntnu.no/Nordsec98/. It has been further polished in DOC - format. (about 18 pages) The published version is in "Nordsec'98 - The third Nordic Workshop on Secure IT Systems", Editor: Svein J. Knapskog, ISBN 82-993980-1-0,

Zimmermann Telegram is Network Associates' newsletter for cryptography-related news and information. Due to the U.S. Government export limitations on cryptographic material, it is available only in print. To receive free subscription to newsletter, send your name and postal mailing address to telegram@nai.com. This information will be used only for the Zimmermann Telegram subscription list. If you want to encrypt your mailing information, please encrypt it to the Zimmermann Telegram Subscription Key (key ID 0xCBA40060). This key can be found on Network Associates' certificate server.
The first issue seems to have been released just before 98/04/14
The secund issue December 4th 1998 is available in electronic form.

(A historical note. There is a famous telegram, which Britain intercepted from Germany to Mexico, which has the same name as this newsletter. This might give false hits when searching for the newsletter on Internet. To read more:
Tuchman, Barbara W., "The Zimmermann Telegram", McMillan, New York, 2nd ed. 1966 (1st ed. 1958.) (A message from Germany offered to restore New Mexico, Texas and Arizona to Mexico if they would fight on the German side in World War I. Decoded, this ensured America's entry into the War. The story of how this information was used, yet keeping the Germans from realizing their codes were broken. Easy reading.)

Links to further info.
- The International PGP Home Page
- PGP Interactions Page, http://www.stat.uga.edu/~rmarquet/pgpvers.html
- PGP-Users Mailing List Home Page, http://pgp.rivertown.net/
- Pretty good links, http://www.cnlab.ch/links/pgp.html
- Robert's PGP Links, A compilation of PGP, Cryptography and Related Links. http://www.interlog.com/~rguerra/www/
- In November -98, IETF has approved, as a proposed standard, the "OpenPGP Message Format", RFC 2440, ftp://ftp.isi.edu/in-notes/rfc2440.txt
- FAQ's at; http://www.pgpi.com/faq/ Se specially the "PGP DH vs. RSA FAQ"

Swedish resources.
- Information av Bill Leksén, POLKO translation bureau, http://www.polko.se/pgp.html
- Svenska PGP sidan, http://www.mc.hik.se/~mid95lsw/PGP/
- Noteringar från SUNET-seminarium om Pretty Good Privacy - PGP, http://poseidon.umdc.umu.se/pgpnoteringar.html
- Svensk nyckelserver, http://www.se.pgp.net/ (närmaste nyckelserver brukar kunna ge snabbast svar)

 


Latest changed March -99, Laszlo Baranyi, lb@qainfo.se