22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Important considerations with Notes IDs<br />

It is important to take good care of Notes IDs. Thus, there are two particular<br />

things that are worth remembering:<br />

1. If a user is no longer able to use his or her Notes user ID file – either because<br />

that person forgot the password needed to decrypt the Notes user ID, or<br />

because the file has been physically lost – any mail encrypted using that<br />

person’s private key is permanently lost (assuming that no re<strong>cover</strong>y of said ID<br />

is possible, as previously discussed).<br />

2. It is important to treat the Notes user ID carefully, since the private key is<br />

contained within the Notes user ID file. If the Notes user ID is compromised,<br />

anyone that has a copy of that Notes user ID can impersonate that user<br />

(assuming that none of the mechanisms for mitigating that circumstance are<br />

used).<br />

Electronic mail message encryption<br />

One way Lotus Notes offers confidentiality is by providing services by which<br />

electronic mail can be easily and efficiently encrypted. The manner in which this<br />

is performed by the Lotus Notes client is illustrated in Figure 6-16.<br />

Figure 6-16 Electronic mail message encryption in Lotus Notes<br />

This is a practical application of the hybrid solution that we <strong>cover</strong>ed in the<br />

security fundamentals chapter. The numbered steps in the diagram are<br />

described as follows:<br />

1. Alice decides to send an encrypted Notes e-mail to Bob. The Notes client,<br />

seeing that the “Encrypt” checkbox is set, generates a random encryption key<br />

(the secret key, which is generally referred to as being a session key, since a<br />

Chapter 6. Public key infrastructures 227

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!