6.6.2       Select key

Select a key for encryption on this dialog page. Available are password-base encryption and encryption with a public key, which can either be taken from a keystore or from an encryption certificate.

Encryption with password

If you select the password-based encryption you are prompted for a password on the last dialog page "Encrypt". This encryption only supports the "AES-256-GCM" algorithm.

Note

Note: Please mind that the password that you will use for encryption is also needed for decryption.

Encryption with public key

Select a public key from a keystore or an encryption certificate on this dialog. All uploaded public keys are displayed in a list. These public keys usually are those of your business partners with whom you want to exchange encrypted files. Hence, only your business partners are able to decrypt the files with their private keys.

Note

Note: You can as well add your own public key, to ensure that you can also decrypt the encrypted files.

Storage location of certificate

·     Button directory Load certificate from file: Click on this symbol to load a public key from a file and navigate to the directory that contains the key. Keystores have the suffix p12 or pfx; certificates have the suffix .cer or .crt. A keystore contains a certificate and the required pair of keys for asymmetric encryption. Please read chapter 9.6 for more information on encryption.

Note

Note: After loading a certificate from a keystore you must enter the PIN for accessing the keystore. As long as this certificate is contained in this list this PIN entry is also necessary after every new start of Governikus DATA Boreum. However, loading a certificate from a signature card does not require a PIN.

·     smart card icon Signature card: This selection is only displayed in case a card reader is connected and a signature card is inserted. Below the symbol the card readers name is displayed as recognised by Governikus DATA Boreum. You can connect up to 10 card readers. In case you want to connect more card readers please read the document about system requirements. Note: A signature card holds encryption certificates. Only the public key of the encryption certificate is displayed.

Note

Note: If symbols of card readers are greyed out in the dialog section "Storage location of certificate" they are not selectable. If you want to use a signature card, you must insert it into a connected card reader. After the card reader has read-in the signature card the symbol is no longer greyed out and selectable.

Note: Public key of a signature card (encryption certificate)

Files are encrypted with a public key and can only be decrypted with a private key. You can use the magnifier symbol on the right-hand side of the key list to display the public key of your signature key and you can as well save your encryption certificate here. You can then send this public key to your business partners with whom you want to exchange encrypted files. You will be the only one who can decrypt files that were encrypted with your public key.

Select certificates

The right side displays all public keys of the certificates uploaded by you. Mark all keys that you want to use for encrypting. You can select keys the same as you can select files, which is explained in chapter 6.3.2. Select all public keys of your business partners for whom encrypted files are intended.

Note

Note: If you want to encrypt one or more files for several business partners mark all of their public keys here. The files are encrypted with all keys in a way that enables each business partner to decrypt the files with their respective private key.

Default

As explained in chapter 6.3 you can save the settings on this page as default. If you use the navigation arrows in the lower right area of the dialog, this dialog is omitted in later validating calls.

Shortcuts on this page

·     Enter = In case the focus is in the table: display selected certificate

·     Del = Remove marked certificate

·     Alt + t = Set focus into table