Skip to content

Sending pgp encrypted Emails #7310

Description

@tacruc

Hi,
I'm think of implementing sending PGP Encrypted Emails, if the user uploads a public key.

I think there are some php libaries one could use to deal with the encryption?
http://php.net/manual/de/book.gnupg.php

And a Private and Public key of the inctance could be safed in the config.php, or is there a better place to store the Private key?

Public key of the user could be ask in the Personal Settings in the email... section.

Are there any other suggesstions?

Activity

  1. schiessle commented on Dec 1, 2017

    @schiessle
    Member

    I like the idea. I think I even suggested something like this already in the past but can't find the issue any more. You would not even need a private/public key for the Nextcloud server. Encrypting mails for a user should also work with the public key of the user only.

  2. tacruc commented on Dec 2, 2017

    @tacruc
    ContributorAuthor

    Yeah, but at least my email programm thant claims, that the email is not signed, but only encrypted, so evereyone with our public key could fake this message. I don't think that it is that much more work, if I could just store it in the config.php.

    I would use inline pgp, because I think it is the easyer way right now and I didn't get any email with attatchment?

  3. tacruc commented on Dec 4, 2017

    @tacruc
    ContributorAuthor

    A WIP branch of this is online.
    https://github.com/tacruc/server/tree/GPG-Email
    PR: #7996

    • Sending encrypted emails
    • Sending encrypted and signed emails
    • signed emails are not displayed on Outlook, but working on GMail mailbox.org and protonmail.com
    • create nextcloud_data/.gnupg and server keys on setup or upgrade
    • allow users to upload public key
    • make listing and managmend of keys nicer (https://github.com/tacruc/keymanager)
    • enable to download servers public key (keymanger/public.asc or keymanager/server.asc)
    • Add autocrypt header to append public key to email, and as attachment
    • create unit tests
    • upload public keys for contacts (WIP branches https://github.com/tacruc/server/tree/GPG-Contacts, https://github.com/tacruc/contacts/tree/GPG-Pubkey)
    • if public key data contains an URL the keydata are downloaded from the url and imported.
    • downloaded vCard doesn't contain the X-KEY-FINGERPRINT
    • use public keys from contacts to send encrypted share by email emails (WIP branch https://github.com/tacruc/server/tree/GPG-Share-By-eMail)
    • use private key signed message to autenticate on share by email
  4. tacruc commented on Dec 9, 2017

    @tacruc
    ContributorAuthor

    The Base functions are ready and working. Now I would have to conntinue with a setup procedure (generating server keys automatical) and the Interface.
    @schiessle Would you mind having a look on the code and giving some feedback?

  5. schiessle commented on Dec 13, 2017

    @schiessle
    Member

    cool, i will have a look 😄

  6. tacruc commented on Dec 19, 2017

    @tacruc
    ContributorAuthor

    Does somebody has an Idea where it would be a good place in the Interface to publish the public key of the server?

    • I think it should be somewhere, where you don't have to loggin.
      Otherwise users getting an shared by email message, but are not registerd at nextcloud won't be able to download the key.

    • I kind of don't want to upload the public key automaticly to a keyserver I think all the test and development instances would just spam the servers.

  7. denics commented on Dec 20, 2017

    @denics

    Hi @tacruc thanks for this. It seems promising and I hope to have some time during holidays to have a look at it.
    I would like to verify if we could apply the same to notes app. It could be really handy to save notes that are encrypted even in the filesystem. Maybe the approach should be global and the PGP service should be integrated in the server and provided as an API?

  8. tacruc commented on Dec 20, 2017

    @tacruc
    ContributorAuthor

    Hi @denics,
    at the moment I have implemented it as a part of the server.
    The problem for the notes app it, that it would requiere to handle the private key of the user.

    So at the moment it is easy implemend the encrypted saving, but loading the note would require the private key.... And if the private key is stored on the server you would kind of bypass your own encryption.

    I still think that there are usecases where it would make sence to have an app which allows to upload and handle private key's. Backend is for this is mostly ready, with the server code. But I don't have the ability (mostly lack of javascript knowlage) to build an app for controlling and handeling the key's.

  9. denics commented on Dec 20, 2017

    @denics

    I do not think this as a limitation but as a security improvement. User will be able to create encrypted notes only from trusted devices (his mobile, his desktop), otherwise his note will not be encrypted.

    Decrypting works on public key anyway, so it will be accessible from everywhere.

  10. tacruc commented on Dec 20, 2017

    @tacruc
    ContributorAuthor

    @denics Sorry can't follow you right now, decrypting works on private key. Otherwise it wouldn't make sence to call it encryption if anybody could read. So People could take notes everywhere but only open on trusted devices they have installed gpg on. Or the could sign on trusted devices and everybody could read. This would make sence than.

  11. denics commented on Dec 20, 2017

    @denics

    @tacruc, sorry I did mean that you will access the encrypted files only from trusted devices too.

  12. tacruc commented on Jan 18, 2018

    @tacruc
    ContributorAuthor

    @schiessle do you mind, or do you know somebody who could having a look if the aproche in GPG-Email is ok? Than I would write phpUnit test and create a pull request.

  13. georgehrke commented on Jan 21, 2018

    @georgehrke
    Member

    @tacruc Do you mind creating a pull-request right away? :)
    This makes it easier to review because you can simply add comments and also improves the visibility, so more people will take a look.

    And you can always push commits to existing pull requests to extend them (to add unit tests later on)

  14. tacruc commented on Jan 22, 2018

    @tacruc
    ContributorAuthor

    @georgehrke didn't want to do it too early. But I think I could do it now. There is one thing which needs to be fixed. What is the best way to prevent the testing of generteKey on every commit? This test is actually generating gpg key's and taking a long time.

  15. ghost removed
    staleTicket or PR with no recent activity
    on Jun 12, 2019
  16. ChristophWurst commented on Aug 20, 2020

    @ChristophWurst
    Member

    Done via #14722 and the app, right?

  17. joekerna commented on Aug 21, 2020

    @joekerna

    How can I do it? I can't find documentation on this feature

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions