"Pretty Good Privacy (or I can't change my passphrase without
remembering my old one!?)"
The presenation covered PGP from beginning to end. Very well done. The
overheads and speaker notes will be online for review. There were a lot
of good questions on PGP raised and there were enough experienced people
present to answer a couple of platform specific questions that Bruce couldn't.
Additionally Leeland Artra provided a few comments on initial set up steps
that should be done for security reasons. The main points were:
- After creating a new Private/Public key pair via PGP certify your own
public key by signing it.
- Make backup copies of your key rings (public and private) and export your
public key for distribution.
- Create an invalidation certificate for your public key (in case your key
is compromised or you forget your complete pass phrase). Export this certificate
from the key ring and put it someplace you can get to it and secure.
- Restore your keyring (by copying back the from the backup). This clears the
invalidation certificate from your actual keyrings.
- Don't forget to update the public servers with your new key as soon as possible.
- generate your public key finger print and add it to your signature line for
all correspondence. (History for authentication is sometimes important.)
All in all it was a very interactive presentation.
The presentation was built in Microsoft PowerPoint and Leeland is working
on getting it into HTML and will be online shortly (about the same time
his presentation on CGI shows up, been busy sorry...)