Promoting GnuPG support for Okular and addition to Gpg4win

Andre Heinecke <[email protected]> Tue, 16 May 2023 12:52:01 +0200
Newsgroups gmane.comp.kde.events
Message-ID <4512826.cEBGB3zze1@teutates>
Hi Team,

over the past months we have worked on integrating Okular with the Software 
GnuPG. We do not think that there are any hurdles left that would keep us 
releasing it with the marker experimental in the next release so we can be 
more public about announcing the plans. 

Attached is a "blogish" or Press Release style draft which I would love to get 
some assistance with. It is of course in our interest to promote our product a 
bit, but this is featured a bit too prominent in the article and could be 
toned down. Esp. for something like a dot story.
Websites etc. are not really a sales channel for us.

But it would be nice to get the point across that there will be an easy to 
purchase version of Okular. Because for some it is really important that they 
have a responsible supplier for each of their installed Software things and so 
they shy away from Open Source. Esp. in the Government it is often times 
easier to just request to buy a license of something that you already have a 
contract with then to get something like Okular installed from the Windows 
Store.

And of course this gives all the voices in government an additional incentive 
to stick to their "we prefer Open Source" words and actually use it. Since 
there can be no longer the excuse that this is just "hobbist software". :)

The Gpg4win integration will also just lead to 150-300k Downloads a month. At 
least as long as we mark it as experimental it will not be installed by 
default, though.


I have also sent a mail to okular-devel to detail our release plans a bit:
https://mail.kde.org/pipermail/okular-devel/2023-May/044426.html


This is the first time for me asking KDE-Promo for assistance so what is the 
process here? Will you open a phabricator ticket where I can then attach 
screenshots?

I can provide a beta of our current installer for Windows and demo 
certificates. And screenshots of course. The source code is anyway public. The 
only thing which I currently cannot provide is a beta of our Appimage. I'll 
try to get around to that this week but our Windows release has priority.


Thanks in advance and best Regards,
Andre

-- 
GnuPG.com - a brand of g10 Code, the GnuPG experts.

g10 Code GmbH, Erkrath/Germany, AG Wuppertal HRB14459
GF Werner Koch, USt-Id DE215605608, www.g10code.com.

GnuPG e.V., Rochusstr. 44, D-40479 Düsseldorf.  VR 11482 Düsseldorf
Vorstand: W.Koch, B.Reiter, A.Heinecke        Mail: [email protected]
Finanzamt D-Altstadt, St-Nr: 103/5923/1779.   Tel: +49-211-28010702
draft-okular-gnupg-announcement.txt (text/plain, 4.8 KB)
# First draft of an announcement regarding Okular in Gpg4win
# probably a bit too long for publication.


Okular to be added to Gpg4win / GnuPG VS-Desktop

With the Gpg4win 4.2.0 release in May, Okular will be added as an optional
component to the Gpg4win installer, in preparation to a later addition
to GnuPG VS-Desktop. This variant of Okular will feature direct integration
with GnuPG.

---> GnuPG VS-Desktop / Company introduction.

g10 Code GmbH is the company behind the matured Open Source workhorse
GnuPG. Recently we were able to convert this into a commercially successful
product with "GnuPG VS-Desktop", which consists mostly of GnuPG and
Kleopatra as the fronted. Together with an Outlook plugin on Windows and
the usual, excellent, KMail integration on Linux. Previously a recipient of
donations, g10 Code is now able to start giving back to the community and recently
became a patron of KDE.

GnuPG VS-Desktop is not only approved for officially restricted
file and mail encryption in Germany (Verschlusssachen – nur für den Dienstgebrauch), but
also in Europe and across the NATO for EU/NATO RESTRICTED documents. It
has a large customer base with hundreds of thousands installations
already across Europe and is easily purchasable in Germany
through either the large public sector IT suppliers or a framework contract with the
federal government.

The free of charge community versions of these packages (without the approval) are
available for Windows under www.gpg4win.org and https://gnupg.org/download/ (Look for
the AppImage).

---> Okular in General

Okular is probably the best open source document viewer there is. Due to its modular
architecture it combines the achievements of several document handling projects in
a single, accessible interface. It has recently been awarded the "Blue Angel" for
eco friendly software.

KDE Promo -> Please expand here :)

We consider Okular to have the highest security standards already, but to reduce
the attack surface even further our packaging will contain a stripped
down edition of Okular that only comes with PDF support and no support
for any active content. [1]

The fully featured Okular from the Windows Store will be promoted by the GnuPG edition
and recommended to anyone seeking the best User Experience.

Added Okular in GnuPG VS-Desktop will come free of charge to our customers. And
enable many people in the industry and public sector to have a supported alternative to their
Adobe reader installed on their systems. Gpg4win with its dominant market share for
file and mail encryption should also greatly promote Okular as an alternative
document viewer for Windows.

---> Why Okular with GnuPG

Since 2021 Okular got support to sign PDFs with Mozilla NSS. This was great already since
before we had to use a proprietary tool on a Windows VM to sign existing PDFs. And
while the laws behind it took effect over the last decade [2] signing PDFs has become more
and more important esp. with the increase in remote work in recent years.

With GnuPG we bring support of our whole backend with all the algorithms available.
Quite important in Europe as this includes support for the preferred Brainpool ECC curves in
Europe as an alternative to the NIST curves.

And where Mozilla might need proprietary PKCS#11 bridges to smartcards GnuPG has completely
open source support for a multitude of smartcards.
And of course we consider the certificate management in Kleopatra to be much nicer and that
it gives users and Administrators much better control about the acceptable certificate authorities.

---> Status and plans

For now we plan to include our edition of Okular in Gpg4win, marked as experimental for the first
release, and we consider this more of a technical demonstration for early adopters
and a basis for future work.

It works, but the User Experience is not really where we think it should be. Especially
the support for qualified signatures and their promotion is lacking, which we consider a core
feature for business and power users.

With added feedback we will continue to improve the support and integration, both in the
backend and in Okular. With a strong focus of stability and reliability accross
the board.

While it is possible with GnuPG to create a self-signed S/MIME certificate based on an
OpenPGP key you will still need an S/MIME certificate as these are the only ones considered
legal. But as there can be usecases e.g. for internal signatures for OpenPGP, too we might
consider to make this easier and better integrated in the future.




1: Anecdote: We have customers that redirect incoming PDFs by Mail, e.g. from Applicants to
a throwaway Virtual Machine, open it there, let it make screenshots of each page and then
resend the pictures instead of the PDF document to the original recipient.

2: https://en.wikipedia.org/wiki/Qualified_electronic_signature
signature.asc (application/pgp-signature, 5.5 KB)
-----BEGIN PGP SIGNATURE-----

iRAdBAATCQ+lFiEEUVvLfWNZh6ukRusW7yBWKr8ykOYFAmRjYFHOxiYAmQGNBFZm
qpUBDACGI+NCayfhevyjO2nsZrO7I6RNKsQlxW7OUL54fPuu/3VOATIx4q4JAjFy
sDS1Zhq9m83dXNtUlpVHrGfPIG01pzLue5ye/4Nc/18cghM58Wp7qDvOW9kF6FVa
tCoNTZH2UCnV42tw8pxaSmQLcF9kEvEbWG8G0L67ypxUj/ZzOYHccnh1lLQw6mgX
k4Xu/UGCNhnuMrgVQUNLamYtgED0hw+wjh1qji+Geyi9vFtXW5T8wnP95846e4FC
bhMyk/4IXx2dIn0ext4cgLed3jhRa+8oJu9DgPKOcK54/7uSvjU7ypNZM87i1NVS
w5bV0U3ZOZsVCbyYpbczd4G8JLRTGVdLohGd+S88Mj/IDAe1jd6HEea5ugbrixe9
Jb2p8lRVBBWkruGp6BUrl2hQoB0iT6Mavr0lELywAeI/VaYoqh1emRKO0KSPHBij
fjDAABpMkOwkd5U02U/Ddf+CHrCvXkY7qosTkQCSmNF318STF6ZnwB7FG6q1bpoq
BxGnrBkAEQEAAbQmQW5kcmUgSGVpbmVja2UgPGFoZWluZWNrZUBnMTBjb2RlLmNv
bT6JAdcEEwEIAEECGwMFCRLMAwAFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AWIQSU
pcmgPC/lyjsJXY4f33I89GK2sQUCXfJLMgIZAQAKCRAf33I89GK2sW/OC/9tnD+R
tMx78HPvT8BsopA2gNY/JrfQOgMQwi1Jaf335NNKAf3+QHgAg6k6GuriXv+W40+y
6qaRHUzuMOPUmN4BmKQvpwdfdbBnaBC6fA+7ii1tOz3MAzdnEERbwwKbMbhqjM/n
I0JhbntXGpWsBhTLanHLmR5UHrjCsAGTe2nHmqzo8v21q7G8QXQnyQRYnqvR00yV
wyoxi+ZigbxhmiPgYqgKGEXVQizP6NJ2oW/WIqlivQdc3t7hj1DJpEC/KXlDn6jP
aL3taspu8bhF1drjSGIQurGnM8+hGLuHLEpt4yeBtPNWs3iNXNVmcIpxyNtUhikh
yLZKnn9k6V1DvqVqI59OtA0Z+I3K1zKL3TGSL5cLblXSdJkR6hqeoc/mpcgXhIpQ
ydsFsIAdBiaz/9zCxKIrjYCDwIGD2xcqpFI0s2Mbs0oHzH7jJK919B45BXvubO2x
nW4wHsy+8gLqriMCiZOMXX+2hFARBs1xt7P0vGEYM63u1pguDC2dgeE0vgC4OARY
ocu2EgorBgEEAZdVAQUBAQdAsWkCnMaOawGHVvV5QQlv8S099d8CsiuH692nc6sV
V0IDAQgHiQG2BBgBCAAgFiEElKXJoDwv5co7CV2OH99yPPRitrEFAlihy7YCGwwA
CgkQH99yPPRitrEHgwv/UGw2NhaFGEPqC4S3CjLDJNBd5TZ9I2fTWamypfgxNltn
I5GaAxyPgrdyG52Zie0ehjDzwhdXHVD774cFdSzOm/uIFj/eNYt0E5Mo+r+7ww4H
wX9zbQTwgdKzBO2w6BWo6CvnHI8ZFELpZQtdp3RNtzqdzdL67kVQM6+kYaG7w8TP
rSB4nNKaHY1w5hYacwdOZ+S8stkiCi6EDQ2HXk2LoNrb0DLRWzA2lVBz+2sde6Xn
aQaRJ7VecXWA9uXl12X9v1/SgYbhuMZRfW6P4md/Qfsf0o+wGbj7gaTSrmT9UNHU
1+zS3AeEeALf2iVievgOjQAGoyx8mtPqCL0d4vKua7YMEifmq9Vl0AzpgETvk5Uy
2kekNtrO4Ixl3aETB6M0D5b838vo/gfI6a7PMnh71egp0iabKoLrhlX6VpCFHVej
a/wN8MHLUfqt+gbByI9Y8RCKoZ8KHnKymFtG75wl+/06uPV6I9znlKUFiwTY+hH6
5sIAjpFcS1Rqat+YCC30iQG2BCgBCAAgFiEElKXJoDwv5co7CV2OH99yPPRitrEF
Aliun0ACHQEACgkQH99yPPRitrH8Bgv/ZWJs0jhubDZ9sUXrDHKu/bjpRfZKtwgQ
UuowaUjiJEfG4nv3SXB8XyoSHQghksuweuvKflHNGl2SC/dNGhLAoZhDeb4BIRXw
2HxJGW1295YB+yu0b4ciQlJUiC/NocYrxHIvRqHfxprbemqpYaDGaevEGRwI4jfS
ktDPoLHAwS6Qfu74oDHrhwqfLF3ZR0X0keGRcpMKEwgy1VYC7sqcKGiWXbeqR7Gw
ZP8jDLbM+jsqZ7WjtyFBgyuMVbNeWC/WAoE0bdI22Z2gN9FAwm4uUIUUzEt1kRH1
oeADClWjrujPQPdrwkgrsEYDNDDF/cAXus2vrzNuvwFHG50rIyfXyjsyM5XTdgvO
0GsWnlJ04Jaxj3zbg3i71h0uTaexCk6BtmvX2ruaT/N0O3U5SRsue1pYEO96g0u9
RJ9V34ljScPi9kJI6jgIuXUjFcr24sHpBvkyxjE7uSDbGZgb8syIwrLLSS+3BAyT
BfNtxv7M5ElhHK4meB76zRiduYFxw0C2uQGNBFZmqpUBDACzVnvJwBRSsVF3enMM
ioWskplVROhGpXdNo3cKasOdTzS1HYysSHhJZ4hYJIF02PHD6l5cr9qSV8EkAlbS
mPx25/k3XHYQSaNFKD5qh2wN2FhiuvuD89tA0I7KnQIVAdM2Y3Bnr6BFcgfhZNDI
UgP3DtIjcLfBQwcMFVyGjolGa4RLPFWB6hpdgHWk+SR8mlNaAKukfPQj5zHkMRr4
qAtg7kVNhdfbzFPo8eM835fFUWoXkZyMvhCG9BW3utz8lu7jMGtaVKjHzf2q75kA
LNng0mgLIIHhvW4Jb7rIDiW9HiARnLNhELz/N8CXoQa+z3w2pAO7xJC2pJGOS7TR
rvM8433P7fZTrC3DKWvAdI1RvmFCOzGBcwdQGWMe70K2z7oOlc8T295as7HKsghM
Xg+qcvMKwoqRUWplFsqWcLPVt/cfe8SAqWxoWxfaKxixHE/q6XrMnZPeG+WaN7TP
amMTg3JAnPG7OYfq4GoklVnfo/RhkKeZtRhsaGj8ACtPkpkAEQEAAYkBvAQYAQgA
JgIbDBYhBJSlyaA8L+XKOwldjh/fcjz0YraxBQJfTfa9BQkSTU2oAAoJEB/fcjz0
YraxrZwL/1AhquNFRtMswxANItJGYENgJcYCWaS7TbpNVtSEPsue1SQuAol4jaLc
cVVz9j5HxUJUO0DQps8MEV1J3tr7x+zwwEjNwmeyr9O6LPrh91p5M4/Ao5d2wi6h
q5bt+90x6Jx0k+I7ziOXuFXJFOhxqyUTOJJm3RpxjQnetGEzUOUhn/R37Lvnt6bN
Zsr5ltz7HsUsEG3xWoq5hCsGFsp84lNkLGlu2Igy1HlFFKWPjD9k3CN0X96gsoOR
DWHyy8y9lkY5E5Fhrd6GZ3aoS3WGCZawgB+F59PrCDqHvzqOvVBXwRdtlQGnkiJN
jEWoguEvfR/VsLiGoGIcty+ctB5xAOTqB9YuzIByeHpdNpKpKeiAdyRYy16zReVX
MRaYrAkOJHGTTSyHD34pIeH/CivOFjSVp6drVaZ7xjtpA9pEzZDrm/cWx4hDCxgq
hxD7tWX7BU58z7gor4zjN04Ce1egSUqgFDPGE5kP5nyk0tYDs7qLH4Z0mnPx1Pmz
3VFE/Af+RbhzBF8sFQsTCSskAwMCCAEBCwMDBBSypMBngGy3e29QRCpponytz3rS
jdA9mMKbR9EAJvt/QJKoi+u60UetdazD6PX+rETXrzmmpqod8WG5WZrS4bLu1ffY
Rz2GdfqDUfG3rA97yc8E/a+swIhcQ+MtOloV2YkCTQQYAQgAIBYhBJSlyaA8L+XK
Owldjh/fcjz0YraxBQJfLBkpAhsCAKEJEB/fcjz0YraxliAEGRMJAB0WIQRRW8t9
Y1mHq6RG6xbvIFYqvzKQ5gUCXywZKQAKCRDvIFYqvzKQ5nqpAX4+seEU7EJ9yUnL
en0dSOIhGUpVsUP0wf2LVkvbroBfbDwfZXwyFYNlL/HvCT2FKFoBewe4u0g1jRgt
snwQldE4duwtgc4CplKh14U6twiZ1QJaSXrkkpqOVRB6vD+m41XcBGwZC/99yV+e
YoOTiTH4jXL8EbmRQ7KTGv6lLPbTIHrdE09zeiRIRuianNPlVIXeTcsfAT70ZpbT
twpRweq0cyYIZlL7NOMO7HQoXh83yWj8FRZjehRAKY+qIpiAcV7NII+h5leIp+jV
FavyocVdWrdCii5UIg5SSQYKaH/U8CD+GtVAIwR0Vjxv7/WWoClGSxcSFporc8Rd
8iVkp6AS3pCNpAYr+fmoBUw4RTLeen2FbNSEuIkrYp6kViUhkQ/ZgGUhvyYUJCxj
R8J1hQcp0EuapEvex9mgA8W+BmpOGRhQOc4QY2fyNg0XsatqiFIslyvfx03Ip05z
B1Xbpj5tLh05lHYvHgp05O2tZ4hM+T1ujUJamgIZq0hq4XG/OgyNCV7CFidQh3yr
ei/J3M23V+8H6VwBHMB2+u/SpUahQHzSr4xrbzvmDy/vCMfh0ohqBgy9NSO7WyOb
snfCd9BecxJIkxuXVt5fvvAopUkMeJ+oerLzl0/AqxX6NzTDQ8QZ40k1mi24dwRf
LB6aEgkrJAMDAggBAQsDAwRAV1i+YgVoDSOsy2MG/lF2vshFFQOy1hiaCAeC6cpJ
udhFy4mSJ0NTezETvAiCsd1XiAww6ABreO6A4USRrBfnOq5eVNEZ6CK8v+WxYFgV
P4lklQik0R9ijv2CWDhCFN0DAQkJiQG2BBgBCAAgFiEElKXJoDwv5co7CV2OH99y
PPRitrEFAl8sHvoCGwwACgkQH99yPPRitrFS0gv/QxfTBAlVlwrwnpFvFjSCWT8X
/bp4vPaDoGpwhzytEyfsgxVD39+Y+8WZY03o3oOrf0iyV7R+Fvv8U0CZ6FOEKDQ0
X//bXxshudanpt6cXVEM9fCTMP025YQAD4UJPrmoW4Y+/Rle41BvNxrycJILDLO4
kR9OPCcu60ZPqrGeF650LKmzRDMoljH61+4z0Re9Kg6Yogncch78VTxbal6t357K
QP1jdGeGJFQUx+tTv3RtT1bXgc6iTdAplcRbEsaAG8GgSiuyor44hcScSoIFI83h
s8v9+KCo5ozXEg+j4pQwjowVI1OcfVHcIGiDcHNNt0YmJ37ccvu/cD3FDCdLDKYo
2Fmm87mMTU4C773ly6lSu9WBHg3bAdjzuz6xkZFFJCurJMhhCQaC4YfFV5LMoAgt
5/N1N7OiOhKa0KMX7EHDPf/wWVyKY2pPhWq88sJ5sqpszTusj/wm8MLwL+zX+pC4
BOBs8EoTbabILrR4+PdsZHfJsufTmN6nqwn6C1bRAAoJEO8gViq/MpDm3eEBgIRs
j9aCiu3SHDWiTCBJAm5T60zr6Cs3li4/dHG73jQi5fgAfgiOk2RRWo/wbXCUWgF9
FCuBrowKoyp3D0y/yZGYD77xMaw/gAv6aA6DiMoM/jZwkBn4gxQ9rWEZCh224waY
=iZY4
-----END PGP SIGNATURE-----