e8973b75c9ab521f76e0071a4a1399df.ppt
- Количество слайдов: 12
Network Security: Lab#4 -1 E-mail Security J. H. Wang Dec. 3, 2013
Objectives • To learn to use e-mail security tools – PGP • To learn the availability of email security libraries – S/MIME – DKIM
Packages & Libraries in this Lab • Packages – GPG 4 win: for Windows • Libraries – Open. DKIM
Experiment Scenario • Signing/verification of files using certificates – Create a new certificate – Encrypt/sign the file “original. txt” into another file “enc. txt” (using sender’s certificate) – Then, we decrypt/verify it and get another file “dec. txt” (using sender’s certificate), and check if the decrypted file is the same as the original file • Sending/receiving e-mails with certificates – Set up email account – Read mails – Send mails
Gnu. PG Privacy Guard • Homepage: http: //www. gnupg. org/ • Version: – 1. 4. 15 (portable standalone version) – 2. 0. 22 (enhanced version, harder to build) • Platforms: Linux/Free. BSD/Windows/Mac. OS X • An implementation of Open. PGP • Installation steps – (skipped)
GPG 4 win • Homepage: http: //www. gpg 4 win. org/ • Latest version: 2. 2. 1 • Open. PGP: an open standard for e-mail security (RFC 4880) – S/MIME also included • Installation steps: – Simply follow the instructions on screen
Other Tools Included in GPG 4 win • Kleopatra: Gnu. PG certificate manager – New certificate – Encrypting/Signing a file – Decrypting/Verifying a file • Claws Mail: a mail reader – Setting up your mail account – Reading mails – Sending mails
Microsoft Outlook Support in GPG 4 win • PGP for Outlook – Gpg. OL 1. 0 can support Open. PGP and S/MIME
Configuring Outlook for S/MIME • • Configure Your Personal Email Certificates Send a Signed Message Read a Signed Message Check the Credentials of a Signed Message Send an Encrypted Message Read an Encrypted Message Get Certificates for Other Users
Open. DKIM • Homepage: http: //www. opendkim. org/ – Latest version: opendkim 2. 8. 4 – C library for DKIM service: libmilter – Also a milter-based filter application: opendkim • Can plug in to any milter-based MTAs: Sendmail, Post. Fix • An open source implementation for IETF DKIM standard (RFC 6376) based on dkim-milter from Sendmail – Library: libdkim – Milter: dkim-milter 2. 8. 3 (plugins to sendmail) • Also includes implementations of – ADSP (Author Domain Signing Practises): RFC 5617 – VBR (Vouch by Reference): RFC 5518
Configuration and Installation • Compilation of opendkim – – – Download opendkim-2. 8. 4. tar. gz tar -xzvf opendkim-2. 8. 4. tar. gz cd opendkim-2. 8. 4. /configure make install • Configuration of opendkim – For signing and verification • Install opendkim and configure your MTA
Summary • Email security – PGP – S/MIME – DKIM
e8973b75c9ab521f76e0071a4a1399df.ppt