3 ms·
The GNU Privacy Handbook does a pretty good job of blending both the how and why of everything. http://www.gnupg.org/gph/en/manual.html http://www.gnupg.org/gp
by kgo 16y ago
The GNU Privacy Handbook does a pretty good job of blending both the how and why of everything.
http://www.gnupg.org/gph/en/manual.html http://www.gnupg.org/gph/en/manual.html
The biggest thing to worry about is that you only want the private key on systems you trust. If you put your private key on a USB stick, and use the local library or computer lab, you've already lost the battle. If you're running a totally infected Win95 machine, you've already lost the battle.
Second biggest thing is to make sure you properly generate a revocation certificate, and a backup, and store them in a location you consider secure. (And maybe that secure location is just a shoebox in your bedroom closet unless you're worried about the NSA or something.) Then if you realize you've done something stupid, you can just revoke the key and create a new one.
Other than that, there's not much to screw up if you follow the default settings when creating a key with gpg.
For email, I would also highly recommend using a local MUA that connects to gmail. Most people use Thunderbird + Enigmail, but there are other options. Enigmail also has a pretty good manual that covers both the how and why.
http://enigmail.mozdev.org/documentation/handbook.php.html http://enigmail.mozdev.org/documentation/handbook.php.html
The various gpg-related mailing lists are also pretty friendly. They're low-traffic enough that people are always happy to answer basic questions; no RTFM replies.