Basic PGP Use for Windows Desktop Clients
John Holstein

This is a "down and dirty" how-to. It's not precise, it's a work in progress and it's not suppose to be a "step-by-step" guide. This is "how I do it", doesn't mean it will work 100% of the time for you, doesn't mean it's perfect.

Taking for granted you've already downloaded and installed PGP, you've followed their basic installation instructions and created your encryption key-pair, we're ready to begin.

Ok. First, you need to copy your PUBLIC key, make sure it's your PUBLIC, NOT PRIVATE key to a text file. It should be located in the PGP directory under c:\program files\pgp or something similar. If you're having trouble finding it, go into the program menu, right click on the pgp icon, click "properties" and check for the location.

When you have the PUBLIC key copied, you would distribute this out to others using PGP. They will in turn use your public key to encrypt messages to you.

It's EXTREMELY important to remember 2 things:

1) NEVER give out your private key!!!!

2) NEVER forget your password.

Now then. Once you have a copy of your private key in an editor, such as notepad, save that to an easily accessible directory or to your desktop. You can also upload this to a website for easy retrieval by people. It's ok to give out the public key to anyone, that's what it's for.

Tell people where it's at on the website or email it to them.

Now then, here comes a tricky part. How do I know 100% that it's your key? I don't, without authentication. The way to do this would be to exchange key "fingerprints" in person OR call the person and exchange fingerprints over the phone, which is less reliable, but in a pinch would be better than nothing.

Now you need a key from someone else to send to. Mine is located here:

You can copy that, copy the entire thing, then right click on the new pgp icon in the system tray, there should be a selection to "add" the key to your keyring. Click that and add the key.

Now then, to create a message, simply write your email/letter/whatever, "cut" it from the email compose window, cut the entire thing....every last character.

Right click on the pgp systray icon and "encrypt and sign" the clipboard, it will ask for a key to encrypt it to, select mine you just added (it's in the list somewhere), it will ask for your pgp password, enter that, then it will seemingly "stop". What it's done, it's taken the original copied compose message and encrypted it, replaced the clipboard with the encrypted message. Now all you need to do is go back to the compose window and "paste" the clipboard contents back in there.... simply right click and click "paste".

Now you should have something that looks like this:

Version: PGP Personal Privacy 6.0.2

qANQR1DBw0oDf9dp0soq4nYQD+wITW85wDkMSxAlKPzFEFb1RHHaFzB+JIvlk/C/ PW0pfygBVy/K2Mx93IMz17Ucjp0ZwTk9UJ7uQrKCRW6DkEIRR6IJtgXd4TZwrsir QDS5N/izYEQGH9+Y2OFKMtNA3WZlwWVB28AtdyN6laXB2PxKdJ3VD6EXpm51b11J MrbhWhbLTgDkDqzZcnrq3q4avyW7ZYwMLPltvZ4TISd9AV/iuEjUwdT3nuGKVFDo 9p5jLLtqVZ/gBTVZ18jU6EWu10bTz7hdJNzpOF0iIngZYAayGQsiVd4Ymac2ugCe B1YnkzxFgb8g6BmIfpPF48ThaBem4JM2jJ218i3esLPYDV34aD7U4fIerU7KHs/D UjRiKGSVuFB6sx0JGeuRpBxp/6P28h+FII/21wEJ0x6QwiHJT4tzBkRysN3VAEhb IQgENoc7uFrkjbwdkvbwsdbcskbdbcskjdbcsjbdcksbdcfbslxkb8qewqoqwedw scsc82345rmac090bqskD5NmCnjETZtpa1T4U0jm+Iik5oBykC8wHwFYbzbnnPGQ XSY3RwItc2OZ6F7gpketeGpl0x1s2BsYN/V49fCoux0qTHUO20Y3Vtl4a8kh613I FTzbhujHP/7Lb34jRNtrZBbWvwM81wS/OWFSArJHQyRjYhXYaQsuRThIqruJWvuJ Eio7PR2kVAlNnu9WTHG43GLJ+bI1ltan/oQ+u/L5NRwTHSRX622KsPWIHCeceA2s DmPvOGoC35ZxamJlfNt+egx0UVCiuwMznxtl9jepDSV99j5B45PMWZR/kef+XTqJ 9wCuNkYW7OyD6fxkjGUQbMQk03ZbN7QTXEv+z9lXaToJ7mh4HoJnxJL4wPqEowEo MvsW2P6vpLFQuxQEkG2NhLkL/IrWCctPHNSHUYlyFQt4hbJOZ6Fvq5SStGbsMu2d AzAg/m0gpHHSznh/h+ZRnBWWxsiOR+q8ydL7W3VgJA2/PcmXD1f6suYlO/kpuCfV vPLeq9uIlxWHIVVtuUYPC6V9mA9piC3aZoFKLLkEwL4A9zdkSQCz3Rdq1AtjETI9 Aqg2OuL1ZKsi+lOUwbX7EHKeWAA4NE5whlnghmiPqD814n5sMI3t412lino+f1HF rrVXZ+wIyaGcSpODZDsU4Ff6cb+ep6ztZ6peVUnOBTiLD1jR32HegSbGmA== =kxKb


That's what an encrypted message looks like.

Note the ------Begin------ and ------END------, these are what tells PGP that it's an encrypted message, without copying the entire message, PGP won't be able to decrypt it. Make sure you copy the whole thing when you receive your PGP encrypted messages.

To decrypt, it's pretty much in reverse. Someone else will encrypt with your public key, your private key on your computer which is known to PGP will be used to decrypt it. Per known techniques, only you should be able to decrypt it, as your public key and password are the only two that should match.

Give it a try, reply back to me, copy something and encrypt it with my key, then I'll walk you back through the process of decrypting if you have trouble.

Email me with questions.

John Holstein, Cotse Helpdesk/Support


