From: Jan Svitok Date: 2007-01-18T17:51:00+09:00 Subject: Re: Securley Transmit Data On 1/18/07, Daniel N wrote: > Hi everyone, > > Being very unfamiliar with encryption and secure transmission I'm at a loss > of how to do this. > > I need to get info from my system to a clients (with many such transactions > for different clients) securely. > > My thinking is firstly to require all clients to provide a public digital > certificate, then when they request the data send something like. > > > > AES key that has been encrypted with PGP using the public key > > > data encrypted with AES using the un-encrypted key > > > > Then when the client recieves the data, they un-encrypt the key with their > private key, and then un-encrypt the data. > > Firstly, is this approach secure? If you implement it correctly, this is the "standard" approach > If it is, does anyone know where I might find some kind of tutorial(s) that > would help me with implementation. > > I don't even know what library to look in... I have answered similar questions in: http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-talk/211073 and http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-talk/219842 Especially notice the link to Handbook of Applied Cryptography The library you are interested in is OpenSSL This might be helpful as well: http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-talk/228214 Maybe instead of using PGP to encrypt, you may want to use stardard PKI (X.509 certificates etc.) - just choose which one is more convenient to you and/or your users (although I assume OpenSSL supports the X.509 better)