Someone gave me their PGP key. How do I send them a message with just the PGP key?

#asknostr

Reply to this note

Please Login to reply.

Discussion

With public key, lookup id on keyserver, which should reveal email address.

use your own pgp to encrypt message to them, send in email

Cool 😎. Thank you πŸ‘

What is a key server? Where do I find it?

A keyserver is a server for storing, retrieving, searching PGP keys. There are several, but due to abuse over years many are defunct

Recommended reading for more understanding: https://www.rossde.com/PGP/pgp_keyserv.html

May be easier to use tools like Kleopatra to connect and do the lookup

Thank you πŸ™

You can look up their associated email using a pgp key server, if they published it.

https://pgp.mit.edu/

All key servers have the same info? πŸ€”

no. they dont sync

So how do I know which server his key is on? Sorry, noob here

If you are a windows user:

https://www.gpg4win.org/index.html

Otherwise, Kleopatra

Thanks, bud! I found this pretty neat write up on the basics of PGP encryption

https://www.varonis.com/blog/pgp-encryption

You have their PGP public key, right? Do you have a PGP keypair of your own? This may be of help. https://scribe.rip/@acparas/gpg-quickstart-guide-d01f005ca99

Thank you πŸ‘

I have their public key and I have my key pair. Thanks πŸ‘

Great write-up πŸ‘

im wondering about this too, they have to give you the email address too right?

example, send me an email heres my public key 9A7ACC17B300E0DD587E5EF84531DB17CD5B71ED

Hey πŸ‘‹

When you generate your key pair, you input your email and that gets tied to the key.

So, just the key is enough … I can look up your email from key servers

ah ok, i see, in this case i did uploaded to keys.openpgp.org but what if i didnt and how would you know which key server i uploaded it to?

I am not sure what happens if you don’t upload your key πŸ€”

But if it’s uploaded to even 1 key server, a user can use a tool like Kleopatra to look up your email. Kleopatra is part of the GPG4WIN software for Windows. It’s a free software for lookup, encryption, decryption

but for me its too much work just to find out an email address πŸ˜‚ , i think the best way is just give an email address and a link to the server to download the .asc file πŸ€·πŸ»β€β™‚οΈ

I’m still trying to understand the moving parts. I understand that PGP encryption has both symmetric and public key encryption. But how does it actually work. From your email or your public key, I can get the .asc file from the key server. Then do I encrypt a message using your .asc file?

yes, the sender and the recievers email clients are doing the encrypting and decrypting of the .asc file. what email client are you using?

I’m using Outlook and ProtonMail

outlook doesnt support pgp unless you have another external app to decrypt asc file

So .asc is the actual file that is used for encryption and decryption

yes basicly youre sending .asc file as attachment (whoever look into your message cant see whats inside the asc file) untile your recieve and decrypt it

How did you get this public key? I created a key pair using Kleopatra and it has created a file but hasn’t given me a string of characters like this

i use thunderbird (email client) it can make you keypair when you add an email account

I think this is your fingerprint?