PGP keysfor every mailbox,automatically.
SecureMail creates PGP keys for every member of a group and renews them before they expire. No software on computers, no calendar for expiry dates, the same fingerprint.
Why PGP fails in companies
Not because of the cryptography, but because of the upkeep.
Keys on every computer
Every workstation needs software, its own key and a backup. A new laptop becomes a risk.
Expiry dates without an overview
Every key expires on a different day. It is noticed when a partner can no longer encrypt.
Joiners and leavers
New employees need a key on day one. Leavers leave one behind that nobody can access.
Encryption depends on people
Whoever forgets the button sends in plain text. A rule that applies to everyone does not exist on the workstation.
How keys are created and kept current
Three steps, set up once.
1. Enable the group
Turn on PGP keys in a group and choose algorithm and validity. Groups from the directory work the same way.
2. A key for every member
Right after saving and then every hour, SecureMail creates a key pair for every address on a verified domain.
3. Renewal before expiry
30 days before expiry, SecureMail extends the key by the configured validity. The fingerprint stays the same.
Built for operations
Six properties that matter with keys.
Same fingerprint
The existing key is extended, not replaced. Correspondents only re-import the public key.
Existing keys stay
Imported keys and keys created by hand are never changed. If one expires, the group shows a notice.
Notices instead of silent failures
If SecureMail would use another address's key for an address, or a pair is incomplete, the group says so.
Own domains only
Keys are only created for addresses on verified domains. Partner addresses in the same group are left out.
Ed25519 or RSA 4096
Modern elliptic curves by default, RSA 4096 for correspondents with very old software. Validity from one to ten years.
Recorded in the audit log
Every creation and renewal is recorded in the audit log, without key material and without passphrase.
Keys per workstation or central
The two common ways to PGP in a company.
Conbool SecureMail | Keys per workstation | |
|---|---|---|
| Software on every computer | none | on every device |
| Keys for new employees | automatic with the group | by hand |
| Expiry dates tracked | renewal 30 days ahead | calendar or chance |
| Private keys | central in the tenant | on endpoints |
| Encrypts without user action | by rule at the gateway | only when someone remembers |
Workstation approach based on the common use of tools such as Gpg4win or Thunderbird.
Frequently asked questions
How do you manage PGP keys centrally in a company?
Does renewal change the fingerprint?
What happens to keys that already exist?
Which addresses receive keys?
How do partners get the public key?
What does the automation require?
See automatic PGP key management
We show how a group receives its keys and what a renewal looks like.