| ![]() |
Sending Sensitive Information to CERTWe strongly urge you to encrypt sensitive information. We can exchange email with you using PGP or DES. We have STE and STU-III telephones and a secure FAX available, all at the secret level. You can obtain GnuPG or PGP from a variety of sources. We also encourage you to check our PGP signature on email and documents. PGPAs a good security practice, users should be sure to validate PGP keys they receive and not trust unvalidated keys. In the past, forged CERT/CC PGP keys have been created and uploaded to public keyservers. It is important to validate your copy of the CERT/CC PGP public key to insure it is legitimate.
Obtaining GnuPG or PGPGnuPGGnu Privacy Guard offers an OpenPGP compliant application that is freely available. You may obtain GPG software from GnuPG's distribution site: http://www.gnupg.org/download.html This site provides details for the most appropriate software based on your operating system. Please note that the version compiled for MS-Windows is a command line version and comes with a graphical installer tool. Graphical installers are also available via the Windows Privacy Tray: http://winpt.sourceforge.net/en/PGP PGP Corporation offers a range of products, including PGP Desktop, which may be obtained for a free 30-day trial period. You may obtain the software from PGP Corporation's download page: http://www.pgp.com/downloads/index.html PGP software includes tools and discussion forums for support, along with an online support portal: www.pgpsupport.com
Checking our PGP signature on mail messages and documentsMany documents developed by the CERT Coordination Center are signed with the CERT PGP key. We encourage you to check the signature to ensure that the document was indeed written by our staff and has not been changed. Note for users of the CERT Advisory mailing list:
DESContact us to set up a shared key. Call the CERT hotline (+1 412-268-7090) on weekdays between 8:30 and 17:00 (EST - GMT-5, EDT - GMT-4). STE/STU-III telephonesOur STE and STU-III telephones handle secret and unclassified sensitive information. Let us know through the CERT hotline (+1 412-268-7090) that you wish to speak with us on the STE or STU-III phones. Please leave your name and telephone number for our COMSEC custodian. The custodian's normal working hours are 8:30 to 17:00 (EST - GMT-5, EDT - GMT-4).
Secure FAXWe can send and accept secure facsimiles. If you need to send us a secure FAX, call the CERT hotline (+1 412-268-7090) on weekdays between 8:30 and 17:00 (EST - GMT-5, EDT - GMT-4).
Last updated May 23, 2008 |






