File Share Encryption

 View Only
  • 1.  Diff between PGP Web messenger and PDF messenger?

    Posted Jul 12, 2012 02:19 AM

    Hi,

    Below is my understanding on PGP Web messenger and PDF messenger.

    1. Web messenger is by default to be enabled in PGP UN for the Gateway email.

    2. If the emails are to be secured through Gateway email, then web messenger/pdf messenger to be enabled.

    3. If web messenger is enabled, then the end/external user after receiving the secured email (there wont be any message content in the received email), he/she has to enroll the passphrase with PGP web messenger server (only one time enrollment for the single external email address) and after enrolling, the message can be read through web messenger web page.

    4. If the PDF messenger is enabled, then the external user receives the email (there wont be any message content in the received email) with PDF attached and he/she has to open the attached PDF to read the message content and the same passphrase which was used to enroll with web messenger to be used.

    5. If the PDF messenger with certificate deliver is used, then he/she receives the secured email along with PDF attached and even one more html page to get the one time password to read that PDF message alone. After clicking that link and up on copying that passphrase, he/she uses the same one to read the PDF message content.

    6. So web messenger is definitely required for the external users (atleast once, theyhave to enroll their passphrase) even through we use the PDF messenger.

    7. Up on receiving the temporary passphrase for a single PDF message, he/she can store the passphrase somewhere in document and offline (without internet connectivity), they can open the PDF message with that passphrase.

    8. Rest all scenarios, the receipient client should have the internet to read the secured email.

    9. Web messenger only used for the secure mail reply.

    10. Web messenger will always be used for all the kind of secure email messaging.

    11. PDF messaging will be used only in the scenarios like "any banking statements" or "any other attachment which needs to be secured over network" and "any financial info" etc.

     

    Pl add any other points, which explains the web messenger and pdf messenger functionalities and their usage in real world.

    Thanks!



  • 2.  RE: Diff between PGP Web messenger and PDF messenger?

    Posted Jul 12, 2012 04:18 AM

     

    Hi,

    Below is my understanding on PGP Web messenger and PDF messenger.

    1. Web messenger is by default to be enabled in PGP UN for the Gateway email.

    By default it is NOT enabled, you have to manually enable it

    2. If the emails are to be secured through Gateway email, then web messenger/pdf messenger to be enabled.

    No, not necessarily, using PDF and Web messenger are the KNF (Key not Found) options.  They dictate what will happen to an email when the recipient does NOT have PGP or a key.

    3. If web messenger is enabled, then the end/external user after receiving the secured email (there wont be any message content in the received email), he/she has to enroll the passphrase with PGP web messenger server (only one time enrollment for the single external email address) and after enrolling, the message can be read through web messenger web page.

    This is correct, first email they receive they will get asked to create a passphrase, then all future email correspondance between that universal server and the recipient will be through web messenger

    4. If the PDF messenger is enabled, then the external user receives the email (there wont be any message content in the received email) with PDF attached and he/she has to open the attached PDF to read the message content and the same passphrase which was used to enroll with web messenger to be used.

    No, with PDF messenger the user will receieve an encrypted PDF attachment.  The passphrase has to be transferred by other means (usually the telephone) PDF Messenger and Web Messenger are 2 different things, I do not believe they use the same passphrase.  You would not want to have the same recipient using both features anyway, it should be one or the other.

    5. If the PDF messenger with certificate deliver is used, then he/she receives the secured email along with PDF attached and even one more html page to get the one time password to read that PDF message alone. After clicking that link and up on copying that passphrase, he/she uses the same one to read the PDF message content.

    No, because then anyone could intercept this unencrypted email, get the passphrase and be able to read all encrypted email between the universal server and that recipient.  The passphrase has to be transferred on a method that is NOT email

    6. So web messenger is definitely required for the external users (atleast once, theyhave to enroll their passphrase) even through we use the PDF messenger.

    No, you can use PDF messenger and not use web messenger if you want.

    7. Up on receiving the temporary passphrase for a single PDF message, he/she can store the passphrase somewhere in document and offline (without internet connectivity), they can open the PDF message with that passphrase.

    Correct, they do not need an internet connection to read the PDF, as long as they know the passphrase.

    8. Rest all scenarios, the receipient client should have the internet to read the secured email.

    If they are using web messenger, yes.

    9. Web messenger only used for the secure mail reply.

    Correct

    10. Web messenger will always be used for all the kind of secure email messaging.

    For KNF options, yes.

    11. PDF messaging will be used only in the scenarios like "any banking statements" or "any other attachment which needs to be secured over network" and "any financial info" etc.

    It's usually so that the recipient can be 100% sure that  the PDF has not been tampered with.  It uses a file fingerprint so that even if 1 byte is different, the fingerprint will be completly different and wont match.

    Pl add any other points, which explains the web messenger and pdf messenger functionalities and their usage in real world.

    Thanks!

    Web messenger is much more popular than PDF messenger.  PDF messenger is really only used for sending secure PDF files that must not be altered, usually financial things.  



  • 3.  RE: Diff between PGP Web messenger and PDF messenger?

    Posted Jul 12, 2012 06:15 AM

    Thanks for the response.

    1, 3, 7, 8, 9 10. Agree with you

    2. "when the recipient does NOT have PGP or a key" when end user doesnt have PGP desktop installed? and when end user doesnt have PGP key meaning from the organization or global key server?

    So again, its based on the key search which we mention in the sender PGP UN policy right?

    4. Pl check once again. I tried in my environment. They both will use the same passphrase and if we enable the setting "PDF messenger, Encrypt All, Secure Reply" then the email will be encrypted with web messenger passphrase of recipient and when user tried to reply back securely, again user has to go through web messenger only.

    5. No. There is an option "PDF messenger, Centificate Delivery, Encrypt All, Secure Reply" which sends the original message as an PDF attached and even the temporary password also an attached html file. Pl check once again in your environment.

    6. Yes, what i meant is that, if the external users doesnt have any key with the sender's PGP UN or PGP Global Key Server, then only end user has to enroll with web messenger, with out which the email will not be sent to end user ina secured manner.

    11. I am not sure, where can i find the use cases for both web messenger and pdf messenger. when can we say that financial related email contents or pdf attachments are even secured with web messenger?



  • 4.  RE: Diff between PGP Web messenger and PDF messenger?

    Posted Jul 12, 2012 06:46 AM

     

    2. "when the recipient does NOT have PGP or a key" when end user doesnt have PGP desktop installed? and when end user doesnt have PGP key meaning from the organization or global key server?

    No, they do not have to have PGP desktop installed to have a key, they could have some other software for key signing, or pgp universal server using gateway email

    So again, its based on the key search which we mention in the sender PGP UN policy right?

    4. Pl check once again. I tried in my environment. They both will use the same passphrase and if we enable the setting "PDF messenger, Encrypt All, Secure Reply" then the email will be encrypted with web messenger passphrase of recipient and when user tried to reply back securely, again user has to go through web messenger only.

    This is only because that username(email address) can be linked to different features inside universal server, they are not both required, you can have just one or the other

    5. No. There is an option "PDF messenger, Centificate Delivery, Encrypt All, Secure Reply" which sends the original message as an PDF attached and even the temporary password also an attached html file. Pl check once again in your environment.

    Does this sound like a secure method of transferring a confidential document?  Just because the option is there does not mean its secure.

    6. Yes, what i meant is that, if the external users doesnt have any key with the sender's PGP UN or PGP Global Key Server, then only end user has to enroll with web messenger, with out which the email will not be sent to end user ina secured manner.

    Correct

    11. I am not sure, where can i find the use cases for both web messenger and pdf messenger. when can we say that financial related email contents or pdf attachments are even secured with web messenger?

    To be honest, there is not a lot of demand for PDF Messenger, Web Messenger is by far in a way the most popular of the KNF options.



  • 5.  RE: Diff between PGP Web messenger and PDF messenger?
    Best Answer

    Posted Jul 12, 2012 07:15 AM

    ok, thanks for the confirmation.