Contract 'EasyGpg' 2016
Work in progress (can change significantly)
Linking to ongoing work related to the contract
- Vision and some user stories (Meeting April 2016)
- Pubkey Distribution Concept (in discussion)
- Components (work in progress)
- User Interface Interaction with GnuPG (work in progress)
Goals
- Improve the user experience of end-to-end cryptography based on OpenPGP for email.
- Design a new trust model that allows to automate key creation and cert exchange inspired by TOFU or TUFC concepts. Use the existing relationship between user and email service provider (ESP).
- Convince email service providers to offer a certificate discovery service for their users. Offer a fallback solution for testing the resulting implementations.
- Implement the email client side for Thunderbird and Kontact Mail.
- Improve the usability for Thunderbird and Kontact Mail by adding comfort options for storing encrypted emails.
Timeline and Results
Scheduled contract time line: Januar 2016 - June 2017
Resulting software improvements or software designs will be developed within the upstream Free Software initiatives as far as possible, in the open and under a compatible Free Software license. GNU GPL v>=2 is the preferred license.
Some contract reports or concepts will be in German. They may be published under a CC-BY-SA license at discretion of the principal.
Mid 2016 the team published the "web key directory" and "web key service" proposals, and improves them with the wider community, see WKD/WKS overview page.
Principal BSI
The German Federal Office for Information Security (BSI) contracted Intevation and g10 Code.
The public tender was published in September 2015. The bid was accepted in the last days of December 2015.
Team
The team consist of the German companies Intevation GmbH and g10 code GmbH. As a subcontractor KDAB (Deutschland) GmbH & Co. KG will help with the Kontact Mail and Kleopatra implementation parts.
Contact
Prefered: via the public channels of Gpg4win or GnuPG.
Alternatively send email to Emanuel (69A911FC) or Bernhard (EFF5D42A) from Intevation. Encryption appreciated. ;-)