Signing & Encrypting Messages

 

In this section:

About Digital Signatures & Encryption

Getting Other People's Certificates

Configuring Security Settings

Signing & Encrypting a New Message

Reading Signed & Encrypted Messages

Message Security - Compose Window

Message Security - Received Window

 

About Digital Signatures & Encryption

When you compose a mail or newsgroup message, you can choose to attach your digital signature to it. A digital signature allows recipients of the message to verify that the message really comes from you and hasn't been tampered with since you sent it.

When you compose a mail message, you can also choose to encrypt it. Encryption makes it nearly impossible for anyone other than the intended recipient to read the message while it is in transit over the Internet.

Encryption is not available for newsgroup messages.

Before you can sign or encrypt a message, you must take these preliminary steps:

  1. Obtain one or more certificates (the digital eqivalents of ID cards). For details, see Getting Your Own Certificate.
  2. Configure the security settings for your email or newsgroup account. For details, see Configuring Your Security Settings.

Once you have completed these steps, you can complete the instructions in Signing & Encrypting a New Message.

The sections that follow provide a brief overview of how digital signatures and encryption work. For more technical details on this subject, see the online document Introduction to Public-Key Cryptography.

 

How Digital Signatures Work

A digital signature is a special code, unique to each message, created by means of public-key cryptography.

A digital signature is completely different from a handwritten signature, although it can sometimes be used for similar legal purposes, such as signing a contract.

To create a digital signature for an email or newsgroup message that you are sending, you need two things:

 

How Encryption Works

To encrypt an email message, you must have an encryption certificate for each of the message's recipients. The public key in each certificate is used to encrypt the message for that recipient.

If you dont have a certificate for even a single recipient, the message cannot be encrypted.

The recipient's software uses the recipient's private key, which remains on that person's computer, to decrypt the message.

 

Getting Other People's Certificates

Every time you send a digitally signed message, your encryption certificate is automatically included with the message. Therefore, one of the easiest ways to obtain someone else's certificate is for that person to send you a digitally signed message.

When you receive such a message, the person's certificate is automatically stored by the Certificate Manager, which is the part of the browser that keeps track of certificates. This is useful because you need to have a certificate for each recipient of any email message that you want to send in encrypted form.

You can also obtain certificates by looking them up in a public directory, such as the "phonebook" directories maintained by many companies.

 

Configuring Security Settings

Once you have obtained an email certificate (or certificates), you must specify the certificates you want to use for signing and encrypting messages.

For information about obtaining email certificates, see Getting Your Own Certificate.

To specify which signing and encryption certificates to use with a particular account, follow these steps:

  1. Open the Edit menu and choose Mail & Newsgroups Account Settings.
  2. Click Security under the name of the mail account whose security settings you want to configure.
  3. Under Digital Signing, click the Select button. (You may be asked to provide your Master Password before you can proceed further.)
  4. A dialog box appears that allows you to select from among your available signing certificates.

  5. Choose the signing certificate you want to use, then click OK.
  6. Follow the same steps under Encryption: click the Select button, select the encryption certificate you want to use, and click OK.
  7. In some cases you may be able to specify the same certificate under Encryption that you specified under Digital Signing; check with your system administrator to find out for sure.

Optionally, you can also indicate that you normally want to sign or encrypt all messages sent from a particular account. These account-specific settings are for convenience only; you can override the default settings for individual messages.

To configure your default signing and encryption settings, start from the Security panel for the account (described above) and select your settings as follows:

When you have finished configuring your mail security settings, click OK to confirm them.

 

Signing & Encrypting a New Message

Before you can digitally sign or encrypt any message, you must obtain at least one email certificate and configure your mail security settings correctly. For background information on these tasks, see About Digital Signatures & Encryption.

The settings specified in Mail & Newsgroups Account Settings - Security determine the default settings for each new Compose window you open when you set out to write an email.

To open a Compose window, start from the Mail window and click Compose. You can immediately identify the default security settings from the presence or absence of these icons near the lower-right corner of the window:

 digital signature iconThe message will be digitally signed (assuming you have a valid email certificate that identifies you).
 digital signature iconThe message will be encrypted (assuming you have valid certificates for all recipients).

To turn these settings off or on, click the arrow just below the Security icon in the Mail toolbar near the top of the window. Then select the item you want from the drop-down list:

  • No Encryption: Choose this to turn off encryption for this message. The message will be sent in the clear over the Internet.
  • Require Encryption: Choose this to turn on encryption for this message. The message will be sent in encrypted form. However, it can't be sent unless you have valid certificates for all recipients.
  • Digitally Sign: Choose this to turn digital signing on or off for this message. A checkmark indicates the message will be signed.
  • Message Security: Choose this to view detailed information about the security status of this message—to help you determine, for example, whether you need to obtain a certificate for one of the recipients.

    To see more detailed information about the message's security, click the key or lock icon, or follow the instructions in Message Security - Compose.

     

    Reading Signed & Encrypted Messages

    When you view a signed or encrypted message in the Mail window, these icons near the upper-right corner of the message header indicate the security status of the message:

     digital signature iconThe message is digitally signed. If there is a problem with the signature, the pen is broken.
     key iconThe message is encrypted. If there is a problem with the encryption, the key is broken.

    To see more detailed information about the message's security, click the key or lock icon, or follow the instructions in Message Security - Received Message.

     


    Message Security - Compose

    This section describes the Message Security window that you can open for any message you are composing. If you're not already viewing Message Security, click the Security icon in the toolbar of the Compose window.

    The Message Security window describes how your message will be sent:

    The Message Security window also lists the certifiates available for the recipients of your message:

    For more information about obtaining certificates and configuring message security settings, see Signing & Encrypting Messages

    To indicate your signing or encryption choices for an individual message, click the arrow beside the Security button in the Compose window, then select the options you want.

    To indicate your default signing and encryption preferences for all messages, see Mail & Newsgroups Account Settings - Security

     


    Message Security - Received Message

    This section describes the Message Security window that you can open for any message you have received. If you're not already viewing Message Security for a received message, follow these steps:

    1. In the Mail window, select the message for which you want to view security information.
    2. Open the View menu and choose Message Security Information.

    The Message Security window displays the following information:

     


    17 May 2002

    Copyright © 1994-2002 Netscape Communications Corporation.