Security Basics mailing list archives

Re: Encrypted emails


From: Vinay Patel <vin1414 () gmail com>
Date: Thu, 10 Mar 2005 16:01:33 -0500

John,

Depending on the size of the organization, developing a PKI
infrastructure should not be an unmanageable "nightmare".

From a deployment perspective, once you have established the key
components of a PKI, user enrollment and certificate management would
be a trivial challenge, especially using the tools provided by several
commercial vendors.

Using PKI, Integration of digital signature and encryption with
traditional email clients is well tested.  If you have a new
partner/customer, a trust relationship needs to be setup only between
the root CAs, hence, the users would never need to configure any
additional keys or trusts.

On the downside of PKI is cost (assuming use of Commercial) and some
learning curve of the product, although the latter affects only the
administrator and not the users.

-V


On Wed, 9 Mar 2005 13:29:35 -0800 (PST), John Madden
<chiwawa999 () yahoo com> wrote:
Hi,

Looking at the potential deployment and solutions for
encrypted emails i had a few questions.

What do large organization do to ensure that email are
securely transfered with a partner/customer for
sensitive data ?

Using public/private keys seems like a whole lot of
problems...

- How do you exchange keys ? Manually ? This might be
ok for a couple of recipient but can you imagine
hundreds/thousunds at different companies...

- PKI, having to deal with the infrastructure could be
a nightmare.

- Employees learning curve....

Are companies using an encryption software that will
encrypt the messages/attachments and transmit the
password to decrypt by phone ?

I would like your comments/suggestions.

Thanks

John


__________________________________
Celebrate Yahoo!'s 10th Birthday!
Yahoo! Netrospective: 100 Moments of the Web
http://birthday.yahoo.com/netrospective/



Current thread: