Re: Promoting GnuPG support for Okular and addition to Gpg4win
Andre Heinecke <[email protected]> Tue, 16 May 2023 17:58:21 +0200
| Newsgroups | gmane.comp.kde.events |
|---|---|
| Message-ID | <1865023.CQOukoFCf9@teutates> |
Hi, On Tuesday 16 May 2023 15:58:47 CEST Paul Brown wrote: > Okay... I have read the post, but still have some questions: Thanks for looking into the topic. I'll try my best to explain a bit more. I'm a bit strapped for time today so I can't do screenshots or a video. Maybe tomorrow. > So the package you deliver to customers comprises cryptographic software, > and will soon come bundled with a hardened version of Okular too, > correct? I see it already includes Kleopatra as its certificate manager. Correct. Kleopatra is both the certificate manager and the Frontend for file encryption / verification etc. > Can you explain how Okular fits into the existing collection of software? For now we are concentrating on PDF signature verification and creation. So if you want to encrypt your PDF according to the laws around restricted documents you would still use Kleopatra to encrypt / decrypt the whole file. It fits into our software because our users need to manage both their private keys (which they use to sign) and their public keys (which signatures are shown as valid) with our Software if they plan to use it. So basically if you can use our Software to decrypt data someone sends you, you will then automatically be able to sign PDF documents using this key. GnuPG also supports Identity cards like [1] without additional drivers. Technically you can generate an S/MIME certificate (S/MIME certificates are whats required for PDF signatures) with any Smartcard GnuPG supports. That includes open hardware like the > Or, even better, can you give me a scenario where a user would prefer to > use the hardened Okular over another PDF reader? Our customers / users manage their certificates independently of the system or Mozilla trust stores and they are usually far more restricted about this. I think you can summarize it like "If you are using GnuPG for S/MIME already or only want to use a restricted set of acceptable certificate authorities for signature verification". So for example as someone in the German government, Adobe reader would show you a document signed by "Olaf Scholz (Bundeskanzler)" as validly signed, even if the certificate was issued by the "China Financial Certification Authority (CFCA) " For a list of certificate authorities included in Windows see: [2] For Mozilla it does not look much better. And those CA's can change unbeknownst to you through an update of Firefox or Windows. It is also much easier to import a specific certificate for you or for someone else in Kleopatra then either in the Windows store or the Mozilla store. So it could just be a user preference. e.g. If you get a certificate from an issuing authority you just double click it, then it will be imported to Kleo and can then be used for signing or verification. GnuPG by default does not have a list of trusted root certificates. GnuPG VS- Desktop comes with an included list of some CAs which are certified by the German government. In the future we will probably extend that to all Certificate Authorities which are allowed to issue certificates according to eIDAS. Most large S/MIME users have their company certificates and these of their partners added in that list, too. Regarding the hardening, they "should" use it when reading any PDF from an unknown source. But this is mostly in regards to be able to use "any" PDF reader in their hardened environments. > Are we talking providing users with > the means to display encrypted documents or for encrypting documents for > sending them safely? No, it is more about "Identity Management" and "Authentication". Encryption we can do for anything without a PDF reader. Well signing, too but for legality the signature has to be embedded within the PDF. > Please excuse my ignorance, as I am not a super-technical person, and I need > to get my head around these things from a user's perspective. No you are making valid points. I can maybe better illustrate this with some screenshots. I hope my explanations make sense. FYI we asked some of our large customers what they would think of the idea of us including a PDF reader and most thought it was a good idea because of the synergies. So this is not a case of just coldly extending our package, there is a demand for this. Maybe to better illustrate that from an end users perspective as with S/MIME the usual case is that the trusted certificates etc are centrally managed: - You work at a company or office and have a smartcard to access your encrypted disk e.g. with Rohde & Schwarz trusted disk. - You use the same smartcard to access your RESTRICTED documents. -> Now you can additionally sign documents with that same smartcard. Or if you have KMail configured for S/MIME signed mail, you can now not only sign your Mails but PDF documents with the same S/MIME setup. Similarly if you have Outlook configured to do RESTRICTED compliant S/MIME with our plugin, you can now sign documents, too. Where previously this would have required different configurations. > Yeah, or we could just enable a shared folder on Collaborate and dump stuff > there. I think we definitely need some screenshots or even a short video to illustrate the workflow. :) A shared folder should not be required for the data, if I have to share some larger data I can just upload into our infrastructure. Best Regards, Andre 1: https://www.d-trust.net/en/solutions/signature-cards 2: https://ccadb.my.salesforce-sites.com/microsoft/ IncludedCACertificateReportForMSFT -- GnuPG.com - a brand of g10 Code, the GnuPG experts. g10 Code GmbH, Erkrath/Germany, AG Wuppertal HRB14459 GF Werner Koch, USt-Id DE215605608, www.g10code.com. GnuPG e.V., Rochusstr. 44, D-40479 Düsseldorf. VR 11482 Düsseldorf Vorstand: W.Koch, B.Reiter, A.Heinecke Mail: [email protected] Finanzamt D-Altstadt, St-Nr: 103/5923/1779. Tel: +49-211-28010702
signature.asc
(application/pgp-signature, 5.5 KB)
-----BEGIN PGP SIGNATURE----- iRAdBAATCQ+lFiEEUVvLfWNZh6ukRusW7yBWKr8ykOYFAmRjqB3OxiYAmQGNBFZm qpUBDACGI+NCayfhevyjO2nsZrO7I6RNKsQlxW7OUL54fPuu/3VOATIx4q4JAjFy sDS1Zhq9m83dXNtUlpVHrGfPIG01pzLue5ye/4Nc/18cghM58Wp7qDvOW9kF6FVa tCoNTZH2UCnV42tw8pxaSmQLcF9kEvEbWG8G0L67ypxUj/ZzOYHccnh1lLQw6mgX k4Xu/UGCNhnuMrgVQUNLamYtgED0hw+wjh1qji+Geyi9vFtXW5T8wnP95846e4FC bhMyk/4IXx2dIn0ext4cgLed3jhRa+8oJu9DgPKOcK54/7uSvjU7ypNZM87i1NVS w5bV0U3ZOZsVCbyYpbczd4G8JLRTGVdLohGd+S88Mj/IDAe1jd6HEea5ugbrixe9 Jb2p8lRVBBWkruGp6BUrl2hQoB0iT6Mavr0lELywAeI/VaYoqh1emRKO0KSPHBij fjDAABpMkOwkd5U02U/Ddf+CHrCvXkY7qosTkQCSmNF318STF6ZnwB7FG6q1bpoq BxGnrBkAEQEAAbQmQW5kcmUgSGVpbmVja2UgPGFoZWluZWNrZUBnMTBjb2RlLmNv bT6JAdcEEwEIAEECGwMFCRLMAwAFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AWIQSU pcmgPC/lyjsJXY4f33I89GK2sQUCXfJLMgIZAQAKCRAf33I89GK2sW/OC/9tnD+R tMx78HPvT8BsopA2gNY/JrfQOgMQwi1Jaf335NNKAf3+QHgAg6k6GuriXv+W40+y 6qaRHUzuMOPUmN4BmKQvpwdfdbBnaBC6fA+7ii1tOz3MAzdnEERbwwKbMbhqjM/n I0JhbntXGpWsBhTLanHLmR5UHrjCsAGTe2nHmqzo8v21q7G8QXQnyQRYnqvR00yV wyoxi+ZigbxhmiPgYqgKGEXVQizP6NJ2oW/WIqlivQdc3t7hj1DJpEC/KXlDn6jP aL3taspu8bhF1drjSGIQurGnM8+hGLuHLEpt4yeBtPNWs3iNXNVmcIpxyNtUhikh yLZKnn9k6V1DvqVqI59OtA0Z+I3K1zKL3TGSL5cLblXSdJkR6hqeoc/mpcgXhIpQ ydsFsIAdBiaz/9zCxKIrjYCDwIGD2xcqpFI0s2Mbs0oHzH7jJK919B45BXvubO2x nW4wHsy+8gLqriMCiZOMXX+2hFARBs1xt7P0vGEYM63u1pguDC2dgeE0vgC4OARY ocu2EgorBgEEAZdVAQUBAQdAsWkCnMaOawGHVvV5QQlv8S099d8CsiuH692nc6sV V0IDAQgHiQG2BBgBCAAgFiEElKXJoDwv5co7CV2OH99yPPRitrEFAlihy7YCGwwA CgkQH99yPPRitrEHgwv/UGw2NhaFGEPqC4S3CjLDJNBd5TZ9I2fTWamypfgxNltn I5GaAxyPgrdyG52Zie0ehjDzwhdXHVD774cFdSzOm/uIFj/eNYt0E5Mo+r+7ww4H wX9zbQTwgdKzBO2w6BWo6CvnHI8ZFELpZQtdp3RNtzqdzdL67kVQM6+kYaG7w8TP rSB4nNKaHY1w5hYacwdOZ+S8stkiCi6EDQ2HXk2LoNrb0DLRWzA2lVBz+2sde6Xn aQaRJ7VecXWA9uXl12X9v1/SgYbhuMZRfW6P4md/Qfsf0o+wGbj7gaTSrmT9UNHU 1+zS3AeEeALf2iVievgOjQAGoyx8mtPqCL0d4vKua7YMEifmq9Vl0AzpgETvk5Uy 2kekNtrO4Ixl3aETB6M0D5b838vo/gfI6a7PMnh71egp0iabKoLrhlX6VpCFHVej a/wN8MHLUfqt+gbByI9Y8RCKoZ8KHnKymFtG75wl+/06uPV6I9znlKUFiwTY+hH6 5sIAjpFcS1Rqat+YCC30iQG2BCgBCAAgFiEElKXJoDwv5co7CV2OH99yPPRitrEF Aliun0ACHQEACgkQH99yPPRitrH8Bgv/ZWJs0jhubDZ9sUXrDHKu/bjpRfZKtwgQ UuowaUjiJEfG4nv3SXB8XyoSHQghksuweuvKflHNGl2SC/dNGhLAoZhDeb4BIRXw 2HxJGW1295YB+yu0b4ciQlJUiC/NocYrxHIvRqHfxprbemqpYaDGaevEGRwI4jfS ktDPoLHAwS6Qfu74oDHrhwqfLF3ZR0X0keGRcpMKEwgy1VYC7sqcKGiWXbeqR7Gw ZP8jDLbM+jsqZ7WjtyFBgyuMVbNeWC/WAoE0bdI22Z2gN9FAwm4uUIUUzEt1kRH1 oeADClWjrujPQPdrwkgrsEYDNDDF/cAXus2vrzNuvwFHG50rIyfXyjsyM5XTdgvO 0GsWnlJ04Jaxj3zbg3i71h0uTaexCk6BtmvX2ruaT/N0O3U5SRsue1pYEO96g0u9 RJ9V34ljScPi9kJI6jgIuXUjFcr24sHpBvkyxjE7uSDbGZgb8syIwrLLSS+3BAyT BfNtxv7M5ElhHK4meB76zRiduYFxw0C2uQGNBFZmqpUBDACzVnvJwBRSsVF3enMM ioWskplVROhGpXdNo3cKasOdTzS1HYysSHhJZ4hYJIF02PHD6l5cr9qSV8EkAlbS mPx25/k3XHYQSaNFKD5qh2wN2FhiuvuD89tA0I7KnQIVAdM2Y3Bnr6BFcgfhZNDI UgP3DtIjcLfBQwcMFVyGjolGa4RLPFWB6hpdgHWk+SR8mlNaAKukfPQj5zHkMRr4 qAtg7kVNhdfbzFPo8eM835fFUWoXkZyMvhCG9BW3utz8lu7jMGtaVKjHzf2q75kA LNng0mgLIIHhvW4Jb7rIDiW9HiARnLNhELz/N8CXoQa+z3w2pAO7xJC2pJGOS7TR rvM8433P7fZTrC3DKWvAdI1RvmFCOzGBcwdQGWMe70K2z7oOlc8T295as7HKsghM Xg+qcvMKwoqRUWplFsqWcLPVt/cfe8SAqWxoWxfaKxixHE/q6XrMnZPeG+WaN7TP amMTg3JAnPG7OYfq4GoklVnfo/RhkKeZtRhsaGj8ACtPkpkAEQEAAYkBvAQYAQgA JgIbDBYhBJSlyaA8L+XKOwldjh/fcjz0YraxBQJfTfa9BQkSTU2oAAoJEB/fcjz0 YraxrZwL/1AhquNFRtMswxANItJGYENgJcYCWaS7TbpNVtSEPsue1SQuAol4jaLc cVVz9j5HxUJUO0DQps8MEV1J3tr7x+zwwEjNwmeyr9O6LPrh91p5M4/Ao5d2wi6h q5bt+90x6Jx0k+I7ziOXuFXJFOhxqyUTOJJm3RpxjQnetGEzUOUhn/R37Lvnt6bN Zsr5ltz7HsUsEG3xWoq5hCsGFsp84lNkLGlu2Igy1HlFFKWPjD9k3CN0X96gsoOR DWHyy8y9lkY5E5Fhrd6GZ3aoS3WGCZawgB+F59PrCDqHvzqOvVBXwRdtlQGnkiJN jEWoguEvfR/VsLiGoGIcty+ctB5xAOTqB9YuzIByeHpdNpKpKeiAdyRYy16zReVX MRaYrAkOJHGTTSyHD34pIeH/CivOFjSVp6drVaZ7xjtpA9pEzZDrm/cWx4hDCxgq hxD7tWX7BU58z7gor4zjN04Ce1egSUqgFDPGE5kP5nyk0tYDs7qLH4Z0mnPx1Pmz 3VFE/Af+RbhzBF8sFQsTCSskAwMCCAEBCwMDBBSypMBngGy3e29QRCpponytz3rS jdA9mMKbR9EAJvt/QJKoi+u60UetdazD6PX+rETXrzmmpqod8WG5WZrS4bLu1ffY Rz2GdfqDUfG3rA97yc8E/a+swIhcQ+MtOloV2YkCTQQYAQgAIBYhBJSlyaA8L+XK Owldjh/fcjz0YraxBQJfLBkpAhsCAKEJEB/fcjz0YraxliAEGRMJAB0WIQRRW8t9 Y1mHq6RG6xbvIFYqvzKQ5gUCXywZKQAKCRDvIFYqvzKQ5nqpAX4+seEU7EJ9yUnL en0dSOIhGUpVsUP0wf2LVkvbroBfbDwfZXwyFYNlL/HvCT2FKFoBewe4u0g1jRgt snwQldE4duwtgc4CplKh14U6twiZ1QJaSXrkkpqOVRB6vD+m41XcBGwZC/99yV+e YoOTiTH4jXL8EbmRQ7KTGv6lLPbTIHrdE09zeiRIRuianNPlVIXeTcsfAT70ZpbT twpRweq0cyYIZlL7NOMO7HQoXh83yWj8FRZjehRAKY+qIpiAcV7NII+h5leIp+jV FavyocVdWrdCii5UIg5SSQYKaH/U8CD+GtVAIwR0Vjxv7/WWoClGSxcSFporc8Rd 8iVkp6AS3pCNpAYr+fmoBUw4RTLeen2FbNSEuIkrYp6kViUhkQ/ZgGUhvyYUJCxj R8J1hQcp0EuapEvex9mgA8W+BmpOGRhQOc4QY2fyNg0XsatqiFIslyvfx03Ip05z B1Xbpj5tLh05lHYvHgp05O2tZ4hM+T1ujUJamgIZq0hq4XG/OgyNCV7CFidQh3yr ei/J3M23V+8H6VwBHMB2+u/SpUahQHzSr4xrbzvmDy/vCMfh0ohqBgy9NSO7WyOb snfCd9BecxJIkxuXVt5fvvAopUkMeJ+oerLzl0/AqxX6NzTDQ8QZ40k1mi24dwRf LB6aEgkrJAMDAggBAQsDAwRAV1i+YgVoDSOsy2MG/lF2vshFFQOy1hiaCAeC6cpJ udhFy4mSJ0NTezETvAiCsd1XiAww6ABreO6A4USRrBfnOq5eVNEZ6CK8v+WxYFgV P4lklQik0R9ijv2CWDhCFN0DAQkJiQG2BBgBCAAgFiEElKXJoDwv5co7CV2OH99y PPRitrEFAl8sHvoCGwwACgkQH99yPPRitrFS0gv/QxfTBAlVlwrwnpFvFjSCWT8X /bp4vPaDoGpwhzytEyfsgxVD39+Y+8WZY03o3oOrf0iyV7R+Fvv8U0CZ6FOEKDQ0 X//bXxshudanpt6cXVEM9fCTMP025YQAD4UJPrmoW4Y+/Rle41BvNxrycJILDLO4 kR9OPCcu60ZPqrGeF650LKmzRDMoljH61+4z0Re9Kg6Yogncch78VTxbal6t357K QP1jdGeGJFQUx+tTv3RtT1bXgc6iTdAplcRbEsaAG8GgSiuyor44hcScSoIFI83h s8v9+KCo5ozXEg+j4pQwjowVI1OcfVHcIGiDcHNNt0YmJ37ccvu/cD3FDCdLDKYo 2Fmm87mMTU4C773ly6lSu9WBHg3bAdjzuz6xkZFFJCurJMhhCQaC4YfFV5LMoAgt 5/N1N7OiOhKa0KMX7EHDPf/wWVyKY2pPhWq88sJ5sqpszTusj/wm8MLwL+zX+pC4 BOBs8EoTbabILrR4+PdsZHfJsufTmN6nqwn6C1bRAAoJEO8gViq/MpDm1kkBf1BB ho7zaB3MHEY7XQDwOei8+mNnjDrIg5FoxUxhm25UYtjOiFsiapAzlh/FO+na7AF/ SKHs7Ljj3C1u+ws7hSiTlnd2JaGXAaRNwQu7JxGi2TIKx2GAWeWxwcNeyVusYrPc =ISY4 -----END PGP SIGNATURE-----