Ciphire Accounts

In the Accounts window you will see a list of your secured email accounts. You can add and remove email addresses using the Add and Disable buttons below the account window.

Add

  1. Click the [Add] button. A dialog window opens asking you to enter the email address you want to secure.

  2. Enter an email address and click [OK]. The window closes and you will see an animated icon in your system tray. Further a tiny status pop-up might appear.

  3. The Ciphire System will now create a DSA, a RSA and an ElGamal key in sequence. The process ends with the message Sending certification request….
    The new email address is added in grey color to the list of already secured addresses in the Accounts field.

  4. When the key creation is terminated, an information message appears, asking you to check your email to see if you have received an email which is an essential part of the creation of your account.

  5. Click the [OK] button in the message window and check if you have received a new email. The first email will inform you that the Ciphire system is processing your certification request. After you have received this first email wait a few minutes and check your email again. A second email will arrive that confirms the certification was successfully completed and your email account is now secured. You will see the email account in black in the Accounts field.

While the key creation and subsequent certification is in progress the new entry appears gray and in italics. During the key creation and certification the status on the right will change from Certificate in creation (...) to Active certificate and the email account itself will turn black in normal typeface.

Disable

  1. Select an email address in the Ciphire Accounts window.

  2. Click [Disable]. A dialog box appears.

  3. Click [Yes] in the dialog box. The Ciphire account for that email address is now being disabled.

  4. A pop-up will appear asking you to check your email.

  5. Click [OK] and check your email to see if you have received a confirmation mail stating that the certificate for the email address selected in step 1 was successfully removed from the Ciphire Certificate Directory.

Attention!

After disabling your Ciphire account you will no longer be able to sign or encrypt emails for this account.

Import

With the Import option you can load account data to the Ciphire Mail user directory. On Windows systems the directory is located at Documents and Settings - [your personal folder] - Application Data - Ciphire. On Unix systems the directory is located at ~/.ciphire.

  1. Select the email address for which you want to import the related account data.

  2. Click the [Import] button..

  3. Choose the file you want to import and click [Open].

  4. Enter the passphrase to decrypt the file.
    This is the same passphrase that was used to encrypt the file when it was exported.

Export

  1. Select the account you want to export in the Accounts list.

  2. Click the [Export] button. A file dialog pops up.

  3. Select a directory, folder or storage device where you want to store the account data.

  4. The system suggests to name the file after the account, - you may as well overwrite this with a different file name.
    Click [Save].

  5. Enter a passphrase of at least 8 characters to encrypt the file (to protect it in case it gets lost or stolen while being moved over to a different computer).

  6. The account data of the selected email address is stored in an encrypted file ready to be moved to a different machine. (See Import for further details).

Info

This option is currently not activated.

Renew

You may renew your certifcates at any time. This is recommended if you have reason to believe that your account data was compromised. To ensure that no unauthorized person can sign, encrypt and decrypt sensitive data, you can renew the certificates of your email accounts.

When you click the [Renew] button, the software will immediately start creating new DSA, RSA and ElGamal keys. This The process bar closes with the message Sending certification request…. The new email address is immediately added below the existing addresses in the bottom of the Accounts field.

Change Passphrase

During the installation of Ciphire Mail you have been asked to choose a passphrase.
To change this passphrase after the installation, please follow the steps below:

  1. Click the [Add] button. A dialog window appears.

  2. Enter the old passphrase in the first line and the new passphrase below. For security reasons the characters you type are represented by placeholders (xxxxxx) and you cannot verify if you entered them correctly. Therefore you are asked to retype the passphrase.

  3. Click [OK].
    If both entries of the new passphrase match, the old passphrase will be replaced by the new passphrase.

Security Strategies

You can change the default security strategies for every email address listed in the Accounts field. You can conveniently select different strategies from a drop-down list. To change the encryption strategies, just click the black arrow in the top field and scroll to the preferred option. For changing the signing strategies, pick a strategy from the bottom drop-down menue. The following options are available:

Refuse unencrypted Choosing this option, Ciphire Mail ensures that every single mail leaving your mail tool is encrypted with the certified public key (certificate) of the recipient. This means that if the recipient does not have Ciphire Mail installed or does not have a valid certificate stored in the global Ciphire Certificate Directory, the email will not be transmitted.
Never encrypt

If this strategy is selected, NO email sent from your mail account will be secured by encryption using Ciphire Mail. Emails will be sent in plain-text and will be vulnerable to any wiretapping.

Try to encrypt Choosing this configuration, Ciphire Mail will attempt to secure all outgoing emails, provided the mail client finds a valid certificate belonging to the dedicated recipient(s) in the global directory. Recipients who do not have an active certificate in the directory will receive all emails unencrypted.
Warn if unencrypted Same as above. Ciphire Mail will attempt to secure all outgoing emails of the selected account. If the Ciphire Mail is unable to locate a valid certificate for one or more of the dedicated recipients, the software will warn the sender with a message saying to which recipient the email will be sent unencrypted.
Never sign Emails leaving your mail tool will NOT be digitally signed. This means the recipient cannot be sure that you sent exactly that email. Nor can you or the recipient prove the exchange of that email to any third parties.
Always sign Emails leaving your mail tool will be automatically digitally signed. The recipient of the email can be sure that you sent exactly this email and both, you and the recipient can prove to third parties that this email communication took place.

Default

The Ciphire Mail client is installed with the following default strategies:

Set as primary

If you have more then one account in the accounts list (left), clicking the [Set as primary] button will set the currently selected account to be your default email address. You primary account will then be displayed in bold letters.

Individual Recipient Strategies

In addition to the generally applied security strategies you can define encryption and signing options for each recipient separately. Click the button [Individual Recipient Strategies]. The Individual Recipient Strategies window opens. Here you can define individual encryption and signing options for each recipient.

  1. In the Encryption tab, enter a recipient's email address and click [Add].
    The new recipient appears below.
    Repeat the process for each recipient for whom you would like to have individual encryption strategies.

  2. Select one of the recipient addresses you have just added. The selected address is highlighted.

  3. Open a drop-down list under Strategy and choose how you want Ciphire Mail to handle emails sent to the corresponding recipient.

  4. When you have made your choices for each of the recipients in this window click [Apply] - the changes are made, your option window stays open - or click [OK] - your changes are made and the option window closes.

  5. Click the Signing tab, enter a recipient's email address and click [Add].
    The new recipient appears below.
    Repeat the process for each recipient for whom you would like to have individual signing strategies.

  6. Select one of the recipient addresses you have just added. The selected address is highlighted.

  7. Open the drop-down list under Strategy and choose one of the email signing options (Do you want Ciphire Mail to automatically sign all emails sent to this recipient or not?).

  8. When you have made your changes for each of the recipients in this window click [Apply]- the changes are made, your option window stays open - or click [OK] - your changes are made and the option window closes.

Signatures

Checkbox: Hide Sender's Signatures

This Checkbox lets you choose to either have the sender's digital signature data attached to the body of an email or not.

If you uncheck the box the software will show the signature at the end of the email body. This will look similar to the example signature below:

---------------------[ Ciphire Signature ]----------------------
From: alice@example.com signed email html-body (3655 characters)
Date: on 02 August 2004 at 11:51:33 GMT
To: bob@example.com
----------------------------------------------------------------
: The message above has been secured using Ciphire Mail.
: Verify this signature and download your free encryption
: software at www.ciphire.com. The three garbled lines
: below are the sender's verifiable encoded signature.
----------------------------------------------------------------
00fAAAAAEAAADFKg5BRw4AABACAAIAAgACACCgF1Q8TG5JzP+fe78FO3KVqEbtQ7
9ZdeehQYMmjPjyVAEAInTVPx1r1ZND1pIHRBoM2ZL4GT6Q4xms62GhuInTFhdjnj
wXLETFoQjTX5qvsKEXlWan4oKmEBBrVqhF7pYBfA==
------------------[ End Ciphire Signed Message ]----------------

Checking the box removes the digital signature from your email body. Ciphire Mail will still check the signature and only mark the message as signed if the signature and the certificate were valid, - however you will not see the signature at the end of the email body.

Checkbox: Remove old signatures

If you did not check the above Remove Sender's Signature checkbox you are able to cross sign documents when you reply to or forward an email. Ciphire Mail will leave the old signatures in place and add your signature below, thereby cross signing the document if the old signature was valid.

If you do not want this behavior please check this Remove old Signatures checkbox to always remove any old signature in replied or forwarded emails.

Security Reports

Checkbox: Mark outgoing Emails

In this box you can choose whether or not to mark the emails you send. Checking this box marks your outgoing emails, while unchecking the box does not mark them.

Marking means a tag will be added to indicate how your email was sent.

You may choose between 2 different possibilities to mark your outgoing mails:

  1. Marking the subject with a long tag, for example [ciphired] or [signed]
  2. Marking the subject with a short tag, for example [se] or [s]

Example:
An email that is sent both encrypted and signed between two Ciphire Mail users will be show a [se] or [ciphired] tag, indicating to the recipient that exactly this message was sent by you and that only you and he could read it .

You should normally never uncheck this box to allow optimum operation of Ciphire Mail System !

Checkbox: Mark incoming Emails

Leaving this box unchecked hides any information indicating the way Ciphire Mail received this email.

Having this box checked will allow you to choose between four different ways of marking your incoming mails:

  1. Subject [long] - you will see a tag (long form) in the Subject: of your incoming emails, e.g. [ciphired].
  2. Subject [short] - you will see a tag (short form) in the Subject: of your incoming emails, e.g. [s].
  3. From [long] - you will see a tag (long form) next to the sender's name or email address, e.g. [signed].
  4. From [short] - you will see a tag (short form) next to the sender's name or email address, e.g. [se].

Checkbox: Add detailed Report to incoming Emails

If you mark this checkbox you will receive a detailed report added to the end or attached to your email message. This report will contain information about the way this message was transported.

An email from a non-Ciphire Mail-User shows the following message:

* Message was not encrypted.

The example below shows the report attached to a message send by alice@example.com to bob@example.com and a copy to carol@example.com with a file attached named biography.doc.

--------------------Begin Ciphire Report------------------------
+ Ciphired message was decrypted.
+ FPL cross check succeeded.
+ Body was signed by 'alice@example.com' for 'bob@example.com,
carol@example.com. Signature is valid.
+ Attachment "biography.doc" was signed by
'alice@example.com' for 'bob@example.com,carol@example.com'.
Signature is valid.
+ Signature was removed from the body.
--------------------End Ciphire Report--------------------------

In Detail:

Default

Clicking this button will reset all security report settings to the default setting, the way all options were marked after installing the Ciphire software the first time.

The default settings are:

[c] Capability Reports

Checkbox: Mark incoming mails

This option is another informational option, the system will check if the sender and the other recipients of any email you receive are using Ciphire Mail. The name or email address of these user will be marked with a [c] showing you they are as well Ciphire Mail users.

When choosing the option normal Ciphire Mail will only do this for encrypted and/or signed mails. Choosing the option always will result in all emails marked in that way.

Checkbox: Mark outgoing mails

This checkbox lets you add the [c] tag, in the way described above, for outgoing emails, indicating to the recipient who all is using Ciphire Mail.

Logging

Checkbox: Log Signatures and Security Reports

You may choose to archive all your signatures and security reports in a monthly new log file. Every email sent or received will be listed here with their signatures attached and if they were secured also with their security report. In fact this means you can activate the Remove sender's signatures checkbox (see above) and deactivate the detailed report checkbox (see above) but still have all the information available in case you need it. The log can be used as a proof, even to third parties.

These log files can be found in the user directory of your Ciphire Mail installation.

On Windows systems: Documents and Settings - [your personal folder] - Application Data - Ciphire - logs

IMAP

Upload to Server

When using an IMAP-Server and storing mails on the server you can, by this selection, choose if Ciphire Mail shall even encrypt these mails stored on your own server. If you select encrypted Ciphire Mail will encrypt all messages with your account data. If you select plain you wont have any further security for these messages stored on your IMAP server.

If you select encrypted, please keep in mind that you will always need Ciphire Mail and your account data to read messages. If you want to read old messages please make sure to never delete any old deactivated keys!

Databases

Private Keys [Change]

This feature is currently not available. It will allow you to store your private account data in a different location.

Delete old Account Data

Clicking this button will delete all old account data (keys) from your database.

When you recently renewed your account you might still receive old mails encrypted with these old keys, so you should not use this function!

Further, if you are using IMAP you might want to decrypt old messages that are left on the server for a very long time, so you should never use this function!

Certificate Renewal

Certficate Renewal Mode

You can choose to handle the Certificate Renewal interactive or completely automatic.

Interactive means you'll be asked - via a pop-up - well before your account data is about to expire, to renew your account.

Setting this option to automatic causes the system to renew your account fully automatic.

Why do accounts have to be renewed at all and how often will a renewal take place?

When you first generate a certificate for a specific email adress, this first certificate will be valid for one month.

This first short time period has been set for your security, to avoid fraud, and in order to keep the central certificate database clear of dummy and testing certificates.

After the first Certificate Renewal your second certificate lasts 12 months and has to be renewed only once a year - similar to a passport that has to be renewed on a regular basis. Additionally this keeps the central database up-to-date and thus ensures maximum performance.

Certificate Verification

Fingerprint List Checking

Here you can select how extensive Ciphire Mail performs the extended validity by Ciphire's unique Fingerprint List Feature (patent pending).

A fingerprint is unique unforgable representation (hash) of a certificate, which is generated every time a certificate is created, renewed or revoked. The entirety of these hashes is referred to as Fingerprint List (FPL). To ensure that nobody, not even Ciphire Labs or any other party can forge or modify certificates or account data this Fingerprint List (FPL) is globally published and crosschecked in between all users of the Ciphire System. Thereby all users have the 100% proof that they all have the same knowledge about the entirety of accounts in the Ciphire System.

Verifying a certificate means that you must download fingerprint list data. To minimize overhead traffic flow and economize the use of bandwidth, you can select different verification modes as described below.

Full

Set to ‘full’, your Ciphire Mail client downloads all fingerprint lists including the final hash of all lists, the cross FPL hash, at the end of each time interval. The full mode is only useful for high traffic use (gateway solutions) in the range of several hundred email communications with different users every day.

On Demand

This is the default and recommended setting. In this mode, the software checks the fingerprint lists only when an email is sent or received. In addition, it checks only those list entries containing the certificate of the intended email recipients. Consequently, this mode does not require as much bandwidth as the ‘full’ mode.

Minimal

You should select this option when bandwidth is limited, i.e. when you are hooked up to the network over a slow dial-up connection, a mobile phone, or a slow WLAN. With the certificate verification set to minimal, the software checks only your own and the authority certificates.

Certificate Chain Check

An unbroken chain of certificates for a certain email address means that this specific email address has continuously, without any interruption, - since the first certificate creation for this email address - been assigned valid consecutive certificates.

In the Ciphire System certificates can only be renewed by the owner of the private account data, so you can be sure that even if the certificate of someone has been renewed it is still the same someone who had created the previous certificate.

You have two different possibilities to check the certificate chains of your contacts:

Predecessor

The system only checks the actual and previous certificate.

Full Chain

Ciphire Mail checks the full certificate chain - from the very first certificate of a specific email address to the actual one.

Certificate Cache

Cache Timeout

Using the Cache Timeout slide bar, you can define for how long you would like the system to cache (store & remember) certificates of your emailing contacts on the local disk of your computer.

It is recommended to cache the certificates so your Ciphire Mail client does not need to look up a certificate on the system every time you want to send a secured message. The default caching period is 2 days. If you are hooked up to network over a slow connection, it is recommended to increase the caching time, as this reduces the bandwidth consumed by Ciphire Mail.

Software Update

Checkbox: Check for Update

This box lets you choose how you want to keep your Ciphire Mail software up to date.

If you leave the box unchecked Ciphire Mail does not automatically check for available software updates. You may still manually update your version via the [Update Now] button on the right.

Having the box checked lets you decide between different ways how Ciphire Mail should handle new updates available for download.

Notify

If you choose this option, you will receive a pop-up-notification, telling you that a new version of Ciphire Mail software is available and ready for download. You will then have to wait till Ciphire Mail downloaded the update.

Interactive

Choosing the interactive option causes the Ciphire Mail to download the newest version and notify you about the new available update. You are then able to install the new version right away.

Automatic

This automatic update function downloads the newest version and installs it automatically during the next restart of your system or when you login.

Ciphire Server

This section of the network lets you manage connectivity to the Ciphire Servers.

In the current beta phase these servers are by default set to betappx0.ciphire.net and betappx1.ciphire.net. The default port 0 will result in Ciphire Mail automatically choosing a usable port.
Please do not change those settings during the beta phase.

In the future you will be able to connect to a Ciphire proxy server of your choice, especially if your ISP or network administrator has set up a local Ciphire proxy.

Proxy Server

This section of the network tab lets you manage your internet connectivity.

In some restricted networks your system administrators might have set up so called http proxies that allow you access to the internet. Your system administrator might either support you with an Automatic Proxy Configuration URL or with an IP and Port number. Please enter these values in the appropriate fields. If you do not know about any http proxy servers leave these fields empty.

Ciphire Mail will automatically try to detect these values from your operating system, so these fields might already be filled with the correct values.

Timeout

This timeout defines how long Ciphire Mail will wait for the server or network to receive or send data.

Please use the slide bar to set the timeout to your personal preferences or the demands of your connection (with a slow connection you may want to set it higher).The default value is 36 seconds.

Active Protocols

In the Active Protocols window, you can select the ports and protocols you wish to use for your secured email communication. By default the following ports and protocols are selected:

SMTP (Simple Mail Transfer Protocol)

for outgoing mails

POP3 (Post Office Protocol)

for incoming mails

SSMTP (Secure Simple Mail Transfer Protocol) for outgoing mails
SPOP3 (Secure Post Office Protocol)

for incoming mails

IMAP (Internet Message Access Protocol)

for incoming mails

SIMAP (Secure Internet Message Access Protocol)

for incoming mails

You can turn these protocols on and off by checking or unchecking the marks in the Active column.

To add a new port to the list, click [Add], fill in the port of your choice and select the protocol this port will use from the drop-down menue. Confirm by clicking [OK]. However you will only have to add ports if your network uses some very special setting, normally the default setting will fulfil all your needs.

Please always make sure the redirector is activated for every port your system uses for mail transport !

Checkbox: Display status pop-ups

If you enable this option Ciphire Mail will display a small window in the lower right corner of your screen while performing actions. This window will inform you about the operational steps Ciphire Mail performs.

Checkbox: Animate Tray Icon

If you enable this option the Ciphire Icon in your traybar will display specific animation reflecting the operations Ciphire Mail performs.

Behavior

This feature is not yet available in the current version of Ciphire Mail.