Help with PGP and RSA for secure FTP transmission

  • Thread starter Thread starter TumblingDice
  • Start date Start date
  • Tags Tags
    Transmission
Click For Summary

Discussion Overview

The discussion revolves around the generation and delivery of PGP and RSA keys for secure FTP transmission of confidential legal agreements. Participants explore the technical aspects of key generation and the appropriate methods for submitting these keys in a professional context, specifically within a Windows and IIS environment.

Discussion Character

  • Technical explanation
  • Homework-related
  • Debate/contested

Main Points Raised

  • One participant expresses uncertainty about generating PGP and RSA keys and seeks step-by-step guidance for proper execution.
  • Another participant suggests that the original poster may be using SSH File Transfer Protocol instead of traditional FTP, emphasizing the importance of key length during generation.
  • There is a proposal that pasting the public keys into a Word document is acceptable, as long as the public key is sent and not the private one.
  • A later reply indicates that the original poster successfully generated the keys and communicated with technical support, confirming that their approach was correct.
  • The original poster mentions using specific tools like Kleopatra for PGP and PuttyGen for RSA key generation, indicating a degree of familiarity with these tools but still seeking clarity.

Areas of Agreement / Disagreement

Participants generally agree on the methods for delivering public keys, but there is some uncertainty regarding the correct protocol (FTP vs. SSH) and the specifics of key generation. The discussion remains unresolved regarding the best practices for key submission and the implications of using different protocols.

Contextual Notes

Limitations include the original poster's lack of experience with PGP and RSA, potential confusion between FTP and SSH protocols, and the absence of detailed instructions for key generation and submission processes.

Who May Find This Useful

Individuals working on secure data transmission projects, particularly those unfamiliar with PGP and RSA key generation, as well as those needing to understand the nuances of secure file transfer protocols.

TumblingDice
Gold Member
Messages
471
Reaction score
47
I've been asked to complete a project that requires secure FTP transmission of confidential legal agreements. Despite a healthy background/experience in data communications in the banking industry, time has passed and I've never used PGP or RSA before. NOTE: Everything will be done under Windows and/or IIS. I have a local IIS server for developing/testing, and a public IIS server (if need be) to support the testing phase.

I need to submit a form to apply for secure connectivity. It's asking for both PGP and RSA public keys that we'll use to download new files

My #1 "void" is how to generate the keys properly. Number #2 is how to deliver them in a professional manner. I've tried on my own, using Kleopatra for PGP generation, and "PuttyGen" on the RSA side. I'm feeling "lost at sea"...

My goal is to completely understand before completing a 'perfect' a software solution, yet I'd appreciate a 'recipe' to follow at the moment, hoping to catch up as I go.

Here is the workflow diagram:
Secure-FTP.png


Can anyone help with step-by-step recipes to create both the PGP and RSA keys, and subsequent steps to "do it the right way"...?

The application form I need to submit is a Word doc with numbered questions to fill in. So - in my response to "Public PGP Key for Data Encryption", should I post the '*.pgp' file to a server and provide a link to it? Or should I just 'paste' the open text of the certificate into the Word doc? (Or maybe both.)

And how to deliver the same for the RSA side? Can I paste the open text into the Word doc, or does it need to be installed on a server and communicated from there? My local server isn't public - so I can install on the public server if that's the correct way to begin?

Much TIA!
 
Technology news on Phys.org
Thanks for the post! Sorry you aren't generating responses at the moment. Do you have any further information, come to any new conclusions or is it possible to reword the post?
 
It looks like you're actually using SSH File Transfer Protocol, which isn't related to traditional FTP and its secure variants. I think your main concern when generating keys is to make sure they're long enough. As far as step-by-step instructions for generating the keys, I'd just google for that info. There are a lot of tutorials on how to do that.

The easiest way to send the public keys is to simply send the text file containing the key, so pasting into the Word document should be fine. Just make sure you send the public key, not the private one.
 
@Greg Bernhardt - Thanks a bunch for the 'bump'. I swallowed my pride Friday afternoon and called the source... Learned that I did everything the right way to generate keys, and the techies were happy to hear from me to complete setup on their end. I'm going to post more to the thread this week for those that follow. ;)

@vela - Thank you for responding! Your info is all "spot on". I used Bing (try it sometime) to locate key generators I felt comfortable with. That went well, and I'll post more info for the PGP and RSA solutions I found RSN. Just as you said, all was "text", yet the files had their own unique extensions. I learned this during my "rapid setup" tech contact :), and communicated the info natively by attaching the PGP and ASC files to an email during the phone call.

All the best!
TD
 

Similar threads

  • · Replies 1 ·
Replies
1
Views
2K
  • · Replies 13 ·
Replies
13
Views
4K
  • · Replies 12 ·
Replies
12
Views
3K
  • · Replies 3 ·
Replies
3
Views
1K
Replies
10
Views
5K
  • · Replies 1 ·
Replies
1
Views
2K
  • · Replies 1 ·
Replies
1
Views
2K
  • · Replies 7 ·
Replies
7
Views
6K
Replies
26
Views
19K