Re: [Dovecot] E-Mail Encryption

2009-07-27 Thread Ed W
to...@tuxteam.de wrote: Let me state it again: nothing is gained with server-side *de*cryption which can't be achieved more easily with disk encryption. Werver-side encryption is another thing... One use case is where you have regulatory or policy determination that certain email should

Re: [Dovecot] E-Mail Encryption

2009-07-25 Thread Tapani Tarvainen
On Fri, Jul 24, 2009 at 09:39:25PM +0100, Frank Leonhardt (t200...@fjl.co.uk) wrote: How much good do your locks do when police comes and wants to confiscate your servers because they suspect one of your users has done something criminal? Do you trust they take as good care of the

Re: [Dovecot] E-Mail Encryption

2009-07-24 Thread Frank Leonhardt
On 19/07/2009 16:03, Tapani Tarvainen wrote: On Sun, Jul 19, 2009 at 03:48:25PM +0100, Frank Leonhardt (t200...@fjl.co.uk) wrote: Encrypting the whole disk is good if the server gets pinched. My servers are behind several layers of hi-tech locks with permanent security guards on the door.

Re: [Dovecot] E-Mail Encryption

2009-07-20 Thread tomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Sun, Jul 19, 2009 at 03:48:25PM +0100, Frank Leonhardt wrote: From: to...@tuxteam.de We do agree that local encryption of messages is a Good Thing [...] Did I forget anything? I think that's a pretty good summary of the situation. Where

Re: [Dovecot] E-Mail Encryption

2009-07-19 Thread Frank Leonhardt
From: to...@tuxteam.de We do agree that local encryption of messages is a Good Thing. But just like that, without context, this phrase just amounts to Marketing Oriented Hand Wawing, sorry. The meat of the discussion (and what was being talked about in this thread is: where do you decrypt?

Re: [Dovecot] E-Mail Encryption

2009-07-17 Thread tomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Thu, Jul 16, 2009 at 09:36:30AM -0500, Justin Krejci wrote: Some companies and governments in the United States at least have very strict policy requirements regarding various aspects of security and encryption. Understandable.

Re: [Dovecot] E-Mail Encryption

2009-07-17 Thread Neal Becker
I've thought that it would be nice if my mail was always converted to OpenPGP encrypted form. My setup is, I use fetchmail to pull in my mail to dovecot. Then I read it using kmail (which supports OpenPGP as well as S/MIME).

Re: [Dovecot] E-Mail Encryption

2009-07-17 Thread tomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Fri, Jul 17, 2009 at 08:04:24AM -0400, Neal Becker wrote: I've thought that it would be nice if my mail was always converted to OpenPGP encrypted form. My setup is, I use fetchmail to pull in my mail to dovecot. Then I read it using kmail

Re: [Dovecot] E-Mail Encryption

2009-07-16 Thread Arkadiusz Miskiewicz
On Wednesday 15 of July 2009, Patrick Domack wrote: The only benefit this would being, is email being saved on the server would be encrypted. Otherwise it offers no protection. I guess if you paranoid that the system admin might read your emails, but then, he can just as easily read them as

Re: [Dovecot] E-Mail Encryption

2009-07-16 Thread Thomas
Arkadiusz Miskiewicz wrote: On Wednesday 15 of July 2009, Patrick Domack wrote: The only benefit this would being, is email being saved on the server would be encrypted. Otherwise it offers no protection. I guess if you paranoid that the system admin might read your emails, but then, he can

Re: [Dovecot] E-Mail Encryption

2009-07-16 Thread Tom Hendrikx
Thomas schreef: Arkadiusz Miskiewicz wrote: On Wednesday 15 of July 2009, Patrick Domack wrote: The only benefit this would being, is email being saved on the server would be encrypted. Otherwise it offers no protection. I guess if you paranoid that the system admin might read your emails,

Re: [Dovecot] E-Mail Encryption

2009-07-16 Thread Seth Mattinen
Tom Hendrikx wrote: Thomas schreef: Arkadiusz Miskiewicz wrote: On Wednesday 15 of July 2009, Patrick Domack wrote: The only benefit this would being, is email being saved on the server would be encrypted. Otherwise it offers no protection. I guess if you paranoid that the system admin

Re: [Dovecot] E-Mail Encryption

2009-07-16 Thread Tapani Tarvainen
On Thu, Jul 16, 2009 at 09:06:19AM +0200, Arkadiusz Miskiewicz (ar...@maven.pl) wrote: On Wednesday 15 of July 2009, Patrick Domack wrote: The only benefit this would being, is email being saved on the server would be encrypted. Otherwise it offers no protection. I guess if you paranoid

Re: [Dovecot] E-Mail Encryption

2009-07-16 Thread tomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Thu, Jul 16, 2009 at 12:51:32AM -0700, Seth Mattinen wrote: [...] Encrypting with a public key is completely reasonable, but for proper security, the decryption should only take place on the client's trusted workstation with their private key.

Re: [Dovecot] E-Mail Encryption

2009-07-16 Thread Jacek Osiecki
On Thu, 16 Jul 2009, Tom Hendrikx wrote: Thomas schreef: Arkadiusz Miskiewicz wrote: On Wednesday 15 of July 2009, Patrick Domack wrote: The only benefit this would being, is email being saved on the server would be encrypted. Otherwise it offers no protection. Actually such encryption is

Re: [Dovecot] E-Mail Encryption

2009-07-16 Thread Justin Krejci
Hendrikx Sent: Thursday, July 16, 2009 2:47 AM To: Thomas Cc: dovecot@dovecot.org Subject: Re: [Dovecot] E-Mail Encryption Thomas schreef: Arkadiusz Miskiewicz wrote: On Wednesday 15 of July 2009, Patrick Domack wrote: The only benefit this would being, is email being saved on the server would

[Dovecot] E-Mail Encryption

2009-07-15 Thread Christian Felsing
Hello, I am new to Dovecot but installation was quite easy, so there is one more LDAP authenticated, Dovecot / Postfix mailbox online, but there is one question left: I would like to set up a configuration, which encrypts every user mail with a unique key. If user logs in, private key should be

Re: [Dovecot] E-Mail Encryption

2009-07-15 Thread Timo Sirainen
On Wed, 2009-07-15 at 18:26 +0200, Christian Felsing wrote: I would like to set up a configuration, which encrypts every user mail with a unique key. If user logs in, private key should be decrypted with user password and every mail user requests should be decrypted with users private key. If

Re: [Dovecot] E-Mail Encryption

2009-07-15 Thread Robert Schetterer
Christian Felsing schrieb: Hello, I am new to Dovecot but installation was quite easy, so there is one more LDAP authenticated, Dovecot / Postfix mailbox online, but there is one question left: I would like to set up a configuration, which encrypts every user mail with a unique key. If

Re: [Dovecot] E-Mail Encryption

2009-07-15 Thread Patrick Domack
The only benefit this would being, is email being saved on the server would be encrypted. Otherwise it offers no protection. I guess if you paranoid that the system admin might read your emails, but then, he can just as easily read them as they come in or out of the system. Quoting

Re: [Dovecot] E-Mail Encryption

2009-07-15 Thread Christian Felsing
So I have to inspect zlib plugin (and Dovecot) code ;-) If plugin knows username, it needs a way to get user password in clear text and of course his username to find and decrypt users private key. These items have to be saved in a secure way, while user is logged in. Obviously there are several

Re: [Dovecot] E-Mail Encryption

2009-07-15 Thread Timo Sirainen
On Wed, 2009-07-15 at 21:42 +0200, Christian Felsing wrote: So I have to inspect zlib plugin (and Dovecot) code ;-) If plugin knows username, it needs a way to get user password in clear text and of course his username to find and decrypt users private key. Username is known. There are