SecureMail · PGP

PGP keysfor every mailbox,automatically.

SecureMail creates PGP keys for every member of a group and renews them before they expire. No software on computers, no calendar for expiry dates, the same fingerprint.

Why PGP fails in companies

Not because of the cryptography, but because of the upkeep.

Keys on every computer

Every workstation needs software, its own key and a backup. A new laptop becomes a risk.

Expiry dates without an overview

Every key expires on a different day. It is noticed when a partner can no longer encrypt.

Joiners and leavers

New employees need a key on day one. Leavers leave one behind that nobody can access.

Encryption depends on people

Whoever forgets the button sends in plain text. A rule that applies to everyone does not exist on the workstation.

How keys are created and kept current

Three steps, set up once.

1. Enable the group

Turn on PGP keys in a group and choose algorithm and validity. Groups from the directory work the same way.

2. A key for every member

Right after saving and then every hour, SecureMail creates a key pair for every address on a verified domain.

3. Renewal before expiry

30 days before expiry, SecureMail extends the key by the configured validity. The fingerprint stays the same.

Built for operations

Six properties that matter with keys.

Same fingerprint

The existing key is extended, not replaced. Correspondents only re-import the public key.

Existing keys stay

Imported keys and keys created by hand are never changed. If one expires, the group shows a notice.

Notices instead of silent failures

If SecureMail would use another address's key for an address, or a pair is incomplete, the group says so.

Own domains only

Keys are only created for addresses on verified domains. Partner addresses in the same group are left out.

Ed25519 or RSA 4096

Modern elliptic curves by default, RSA 4096 for correspondents with very old software. Validity from one to ten years.

Recorded in the audit log

Every creation and renewal is recorded in the audit log, without key material and without passphrase.

Keys per workstation or central

The two common ways to PGP in a company.

 
Conbool SecureMail
Keys per workstation
Software on every computer
none
on every device
Keys for new employees
automatic with the group
by hand
Expiry dates tracked
renewal 30 days ahead
calendar or chance
Private keys
central in the tenant
on endpoints
Encrypts without user action
by rule at the gateway
only when someone remembers

Workstation approach based on the common use of tools such as Gpg4win or Thunderbird.

Frequently asked questions

How do you manage PGP keys centrally in a company?
Through an email gateway that holds the keys and encrypts and signs by rule. In Conbool SecureMail, keys are created automatically per group and renewed before they expire.
Does renewal change the fingerprint?
No. SecureMail writes new self-signatures with a later expiry onto the same key material. The fingerprint depends on the key material and therefore stays the same.
What happens to keys that already exist?
Nothing. Imported keys and keys created by hand are never changed, and no second key is created for an address that already has one. If such a key expires, the group shows a notice.
Which addresses receive keys?
All group members with an address on a verified domain of the tenant. Addresses on other domains are skipped.
How do partners get the public key?
The public key can be downloaded from key management and shared. Optionally, SecureMail imports partners' public keys automatically from inbound signed messages.
What does the automation require?
A SecureMail licence. Enabling or changing it in a group additionally requires the permission to import PGP keys.

See automatic PGP key management

We show how a group receives its keys and what a renewal looks like.