home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
Ian & Stuart's Australian Mac 1993 September
/
September 93.iso
/
Archives
/
Utilities
/
Security - care
/
Encrypt
/
RIPEM Mac 0.8b2
/
For users of previous versions
< prev
next >
Wrap
Text File
|
1993-06-19
|
3KB
|
87 lines
Notes for users of previous versions
----------------------
These notes should help bring users of 0.8b1 up to date with the most
major changes in 0.8b2.
New certificates for the TIS PCA and the RSA Low Assurance PCA are available
in the Bootstrap file.
0.8b2 now supports triple encryption for extra security. Note that it
is only compatible with RIPEM Mac 0.8b2 and Mark Riordan's RIPEM 1.0.8
or later. Triple encryption is not part of the PEM standard as of yet.
----------------------
These notes should help bring users of 0.7b1 up to date with the most major
changes in 0.8b1.
The biggest change from 0.7b1 to 0.8b1 is the addition of support for PEM
certificates in 0.8. Certificate Revocation Lists (CRLs) are not yet
supported however.
To obtain a certificate for yourself, do the following.
• Find a Certification Authority who will issue you a certificate.
RSA runs a Persona CA which you may use if you wish. The Persona CA
issues certificates on a first come first served basis and does not
purport to authenticate any identities.
• Assuming you have a RIPEM key pair, choose Create Self-signed Certificate
from the Keys menu. Select the key pair from which to generate your
certificate. (The public component of that key pair will be included
in your certificate.) Fill in the appropriate certificate information
as directed by your Certification Authority.
For the RSA Persona CA, use the following:
+ Country: US
+ Organization: RSA Data Security, Inc.
+ Organizational Unit: Persona Certificate
+ Common Name: <whatever you want>
+ Expiration Date: <within 2 years>
(You should not fill in any of the other fields!)
• Save your self-signed certificate and deliver it to your certification
authority in accordance with its instructions.
For the RSA Persona CA, email it to persona-request@rsa.com.
• When you receive your issued certificate from your certification authority,
decrypt it. You will automatically be asked whether to add the certificate
to your private and public directories.
Note that you will need to designate certain certificates as "Valid by
Declaration" and all certificates considered valid must have certificate
paths which end in such certificates. The Bootstrap file includes some
certificates which you may want to designate as Valid by Declaration and
install in your PublicDirectory file.
Please see the documentation for more details.
To decrypt/verify messages with PEM certificates, you do not need to do anything
special. However, as new certificates are encountered, you will be given the
opportunity to add them to your PublicDirectory assuming that the Add new PEM
certificates to PublicDirectory option is checked in Preferences.
To sign messages with PEM certificates, make sure that the Use PEM mode when
possible option is checked in Preferences. PEM mode will automatically be
used if you are merely signing a message when this option is checked.
To encrypt messages with PEM certificates, you must have PEM certificates for
all the recipients. The appropriate mode, PEM or RIPEM, will be used depending
on what you have for the recipients.
There are new BBEdit extensions for use with 0.8. You should replace the old
extensions with these new ones.