Introduction
Over the next few months, I will be exploring computer cryptography: certificates, chains of trust, certificate authorities, encryption, digital signatures, and the like.
These subjects can seem intimidating, but they are part of the technology we rely on every day. In this article, I want to focus on the basics of public-key cryptography, specifically how key pairs can be used with email. In a future articles, I’ll look at other applications, including HTTPS in your web browser.
Public-key cryptography forms the basis of any number of security systems people encounter every day, making it a useful place to begin. The subject is often presented using dense terminology, jargon, and complicated mathematics. My goal is to keep these things short, clear, and approachable, while adding detail where it matters.
This series will focus on the practical use of public-key cryptography in networking, beginning with the role of PGP or OpenPGP key pairs in email.
History
Before public-key cryptography was introduced in the 1970s, most cryptographic systems used symmetric keys. In a symmetric-key system, the communicating parties share a secret key that is used to encrypt and decrypt information.
This works well when the parties already have a method in place to share the key. The difficulty occurs when many people or systems need to communicate. Each participant must receive, protect, rotate, and eventually replace the necessary secret keys. As the number of participants grows, securely managing all of those shared keys becomes increasingly difficult.
Public-key cryptography introduced a different approach. It uses a mathematically related asymmetric pair of keys:
- a public key, which can be distributed openly
- a private key, which must be kept secret
Depending on the algorithm and protocol, key pairs can be used for digital signatures, authentication, encryption, or key agreement.
Public-key operations are generally requier more computer resources than symmetric-key operations. For that reason, modern network protocols commonly use public-key techniques to authenticate parties or establish a symmetric session key. Symmetric cryptography then protects most of the data exchanged during the session, because it is much more efficient.
Email encryption follows a similar pattern: public-key cryptography helps protect or establish the key, while symmetric cryptography efficiently encrypts the message itself.
The mathematics behind public-key cryptography is interesting, but it is beyond the scope of this presentation. Here, the focus will be its practical use with email.
Encrypted Emails
The first thing I want to do is walk through setting up and sending an encrypted email attachment. Email encryption is different from HTTPS because the two technologies protect different things. HTTPS protects data while it travels between a web browser and a website. OpenPGP can provide end-to-end encryption for a message or attachment intended for a specific recipient.
In this example, the sender uses the recipient’s public key to encrypt the content. The recipient then uses the corresponding private key to decrypt it.
OpenPGP normally uses a combination of two types of cryptography. It encrypts the actual message or file with a randomly generated symmetric session key. It then encrypts that session key with the recipient’s public key. This combines the convenience of public-key cryptography with the efficiency of symmetric encryption.
I will create an OpenPGP key pair in one of two ways: from the command line using GnuPG, commonly called GPG, or through Thunderbird’s built-in OpenPGP features. Thunderbird can generate a new key pair or import an existing one.
Many mail clients provide OpenPGP support directly or through integration with gpg. However, because I am using Thunderbird, I will demonstrate the process with Thunderbird. If you use another email client, you will need to adapt these steps rather than follow them exactly.
Before creating the key pair, let’s walk through an example.
An Example
Juan needs a log file from one of the company’s servers for an investigation. The log file could contain sensitive information related to the investigation. Mary is the server administrator and has access to the server logs.
Juan sends Mary an approved investigation-access request and includes his OpenPGP public key.
Mary retrieves the relevant log file from the server and uses Juan’s public key to encrypt it. She then attaches the encrypted file to an email and sends it to Juan.
In this example, only the attachment is encrypted. The email’s subject and body are not encrypted, and the surrounding email metadata—such as the sender, recipient, routing information, and timestamps may also remain visible. Transport encryption, such as TLS, may protect the message while it is being delivered, but that is separate from OpenPGP end-to-end encryption.
Once the file reaches Juan’s computer, he uses his private key to decrypt it. Anyone who obtains only the encrypted attachment should not be able to read its contents without access to Juan’s private key and, in most cases, its passphrase.
Command Line Key Pairs Managment with PGP
As with any command line utility in Linux the first thing to do is check if it is installed. The package is probably called gnupg, but check your distributions repository to be sure. On Debian you can check if it is installed, and install it if not with these commands.
apt list --install gnupg
apt install gnupg
The second thing to do is check the man page. Most likely once installed it will be referred to as gpg, the command instead of gnupg, the package name.
man gpg
There is also help information available from the command itself.
gpg --help
If gpg was already installed, you will want to look at what keys are currently being managed. Since there are both public and private keys, there are separate commands to list them.
gpg --list-keys
gpg --list-secret-keys
Not every public key will have a corresponding secret key. If you subscribe to services like VPN’s or media services, they may have sent you their public key. Because their private keys are private, you will not have them.
You can also delete keys. For example if you no longer subscribe to a service, you probably want to delete their public key. Odds are they did not do it when the related application was de-installed. On a personal note I recommend deleting any private keys before the corresponding public keys if they exist.
You will need the key fingerprint, which can be acquired with this command.
gpg --fingerprint
Use the following commands to delete keys form your gpg key ring.
gpg --delete-key Full-Key-Fingerprint
gpg --delete-secret-key Full-Key-Fingerprint
Note you will be asked to confirm deletion. In the case of a secret key, you will be asked several times. Make sure you have selected the correct key
To generate a new key pair, we use the following command.
gpg --full-generate-key
You will be asked a series of questions. Follow the prompts to choose a key type and, if applicable, a key size and expiration date. RSA is widely supported, but other algorithms may be suitable to. This will depend on compatibility with the systems and software you’ll use.
Enter your name, email address, and an optional comment when prompted.
You’ll also be asked to set a passphrase. Leaving it blank means the key won’t be protected by a passphrase, kind of defeating the purpose here
The program will then generate your public and private keys and attache them to the gpg keyring.
Another common task you may need to do is exporting your keys for use elsewhere. You will need your key Fingerprint. This is done with the following commands, for each private and public key. Note you can name the key files anything you want.
gpg --armor --export Full-Key-Fingerprint > MyPublicKey.asc
gpg --armor --export-secret-keys Full-Key-Fingerprint > MyPrivateKey.asc
Note the key cypher’s will be displayed on the screen as well as saved to files. Make sure to protect your private key.
That should be the majority of commands you may use.
Thunderbird and gpg
The first thing I need to state up front is that not every email client is the same. Email clients handle things differently. The steps in Thunderbird may differ from those in KMail, Geary, Evolution, etc. Treat this section as a general guide, and adapt the instructions to your email client.
The Second thing I want to state up front, Thunderbird includes its own OpenPGP key manager. Keys you use in Thunderbird are stored in your Thunderbird profile, not in your system’s GPG key ring. You can import keys from your GPG key ring into Thunderbird. And they will be stored and used from your Thunderbird profile.
Access OpeGPG: To open the key manager, select Account Settings for one of your configured email accounts, then go to End-To-End Encryption. You’ll need to set up an OpenPGP key pair for each account that needs to send encrypted email.
View Existing Keys:To view existing OpenPGP keys in the profile, select OpenPGP Key Manager. From there, you can manage or delete keys.
Add a Key: To add a key, select Add Key. You can either create a new key pair or import an existing one. To import a key, export a .asc file form gpg, and then inport it into Thunderbird.
Create a Key Pair: When creating a key pair, Thunderbird automatically creates an identity based on the account’s username and email address. You can also set the key’s expiration date, which defaults to three years, and choose the key type and length. When you’re ready, select Generate Key.
You’ll return to the End-To-End Encryption page, where your new key will be listed. You can also choose to publish your public key to a keyserver.
Encrypting an EMail: Next, I’ll compose a short email with an attachment and address it to one of my other accounts. In the email. from the OpenPGP menu below the menu bar, I can choose whether to encrypt the subject and whether to digitally sign the message. Once I’ve set the options, I’ll send the email.
One important detail: keys are stored in the Thunderbird profile, so they are available across the email accounts configured in that profile. In this example, the message appears encrypted in the recipient account, but Thunderbird can decrypt it because the profile contains the corresponding private key.
If I delete that key pair and have no backup, Thunderbird can no longer decrypt the message.
Conclusions
In this article, we have looked at the history of encryption, especially asymmetrical encryption keys. We have also looked at using GnuPG from the command line to manage key pairs. Additionally we looked at directly managing key pairs in an application like the Thunderbird Email client.
I have tried to keep a end user perspective here and avoid a lot of jargon. The aim is using the technology, without necessarily fully understanding it. That seems to be the place most users are at.
I will be the first to admit, I don’t encrypt a lot of emails. But the few I do encrypt, I feel much more secure about. So I feel it is a necessary skill set to develop.
I really long for the good old days when there were not so many bad actors, and the internet was a much freer place.



Leave a Reply