Automate OpenPGP and GPG Encryption

GoAnywhere MFT lets you protect sensitive files and automate OpenPGP and GPG-compatible encryption workflows. Encrypt, decrypt, sign, verify, transfer, and manage keys from a centralized enterprise platform.

What is Open PGP?

Text

OpenPGP is an open standard for encrypting and digitally signing files and messages. It defines interoperable formats for encrypted data, signatures, and keys. The term  “OpenPGP” is commonly used to describe tools, features, and solutions that support open-source PGP encryption technology.

OpenPGP gives developers a way to include PGP in software that often are free to the public. To do so, developers and vendors who include OpenPGP in their software solutions must follow IETF (Internet Engineering Task Force) standards and allow for easy integration with other OpenPGP-compliant software vendors.

Keep reading: OpenPGP, PGP, and GPG: What is the Difference?

How Open PGP Works

Media
Image
How OpenPGP works
Text

Open PGP uses asymmetric (public key) cryptography and addresses the issues of data authentication and non-repudiation through the ability to "sign" files via embedded digital signatures. When implemented with appropriate algorithms, key sizes, and key-management practices, OpenPGP can provide strong confidentiality and integrity protection. These features give organizations a high level of data protection, making Open PGP one of the most popular file encryption methods used today.

Why Use OpenPGP File Encryption?

OpenPGP file encryption, like standard file encryption with PGP, lets you store sensitive information or transmit information across unsecure networks (i.e., the internet or email) so only the intended recipient can read it.

Organizations use OpenPGP to protect sensitive files before they are transferred, stored, or exchanged with external partners'. Because encryption is applied at the file level, the file can remain protected independently of the transport method used to move it. Examples of enterprise use cases include:

  • Partner file exchange
  • Financial data
  • Healthcare information
  • Batch files
  • Reports
  • Data exports

Who Uses OpenPGP?

Open PGP software is used by banks, financial institutions, healthcare organizations, and other industries to protect their most sensitive files. OpenPGP is especially useful when organizations exchange sensitive files with partners that require PGP-compatible encryption. Some common examples of such files are:

  • Payment files
  • Claims files
  • Customer data
  • Financial reports

Use OpenPGP for Free Today

Encrypt, decrypt, sign files, and verify documents with GoAnywhere Open PGP Studio, a free encryption solution for IT users and teams.

Try it Today

PGP Keys

Text

OpenPGP uses asymmetric encryption, meaning a public key is used to encrypt data and a private key is used to decrypt messages. By contrast, symmetric encryption uses the same key to encrypt and decrypt messages:

  • Anyone can use a public key.
  • Private keys are known only to each user.

Encrypted data that is protected with either symmetric or asymmetric cryptography travels to the recipient who then must use PGP to decrypt the message. Data is authenticated with digital signatures using public key cryptography to ensure data is coming from the source expected and is not tampered with.

The digital signatures travel alongside the message body and use an algorithm to marry the sender’s private key with the data to be authenticated. This makes it virtually impossible to forge unless the private key is compromised.

TaskKey Used
Encrypt for a recipientRecipient's public key
Decrypt received dataRecipient's private key
Sign a fileSender's private key
Verify a signatureSender's public key

How PGP Works to Send or Receive Files

  • Sending files: With PGP, the sender needs access to the recipient’s public key. The session key gets encrypted with the sender’s public key and is decrypted by the recipient with their private key.
  • Receiving encrypted files: The sender will need your public key. Asymmetric keys work by sharing your public PGP key with anyone who will send you encrypted information. The sender will encrypt their files using your public PGP key and you then decrypt them with your private key.

GoAnywhere MFT’s OpenPGP Key Manager is an efficient way to create, export, and manage PGP keys.

Protecting PGP and PGP Keys

Administrators can set expiration dates for PGP keys to help maintain security. In addition, revocation certificates can be used to invalidate a public key, should a private key pairing be compromised. Poor key management can lead to failed transfers, partner disruptions, unauthorized decryption risks, and operational outages. 

Establishing and following best practices around key management can go a long way towards protecting encrypted data and is easier with the automation features found in GoAnywhere’s key and certificate management system.

What is PGP?

Text

PGP, Pretty Good Privacy, is a standard option for file encryption and authentication. It is currently owned by Symantec, a technology company that develops and sells software solutions.

PGP is used to encrypt files to secure them for file transfer. It uses several encryption technologies, including hashing, data compression, and public/private keys to protect sensitive information. PGP is a flexible solution for today’s cybersecurity needs: it is often used to encrypt files before exchanging them with trading partners or remote locations and can also encrypt emails, directories, and disk partitions.

How Secure is PGP?

Media
Image
What is PGP
Text

PGP uses a combination of encryption methodologies, including hashing, data compression, symmetric-key cryptography, and public-key cryptography to secure data. It can be used to encrypt:

  • Text files
  • Emails
  • Data files
  • Directories
  • Disk partitions
  • Reports and business documents
  • Files exchanged with trading partners
  • Application and system data exports
     

Ultimately, OpenPGP can provide strong file protection when organizations use appropriate cryptographic settings and manage private keys securely.

 

How PGP Encryption Works

By transforming plain, readable text into a complex code of unreadable characters, PGP file encryption provides essential privacy missing from online communication. Once encrypted—hashed, data compressed, and “locked” via either symmetric private key cryptography or asymmetric public key cryptography—the message travels to the recipient fully cyphered. The recipient then uses PGP to decrypt the message.

With this system, each user has both:

  • An encryption key that is publicly known and can be provided to the recipient
  • A private key that is known only to each user and should be kept secret

The public key encrypts the message or file, while the private key decrypts.

This encryption standard addresses the issues of data authentication and non-repudiation through the ability to "sign" files via embedded digital signatures. Digital signatures use public-key cryptography to authenticate that data is coming from the source it claims to be from and has not been tampered with. Digital signatures are sent alongside the message body and work by using an algorithm to combine the sender’s private key with the data they are authenticating. The process makes digital signatures essentially impossible to forge unless the private key has been compromised.

Keep reading: Everything You Need to Know about PGP Encryption

 

Sending Files with PGP

PGP is used to encrypt or decrypt the file you exchange and having a trustworthy PGP software is paramount.

For sending files with PGP, the sender will need to have access to the recipient’s public key before they can send their files. Once the file is compressed, PGP will efficiently encrypt the plaintext with private key cryptography, turning the message into ciphertext. The session key is then encrypted using the sender’s public key. Once the recipient has received the encrypted file, they can decrypt it using their private key.

 

The History of PGP

PGP was developed in the early 1990s by Phil Zimmermann & Associates, LLC as a method of securing files that were posted on pre-internet bulletin boards. PGP has changed ownership several times between the 90s and now, and is currently owned by Symantec.

PGP gained popularity because it was initially available freely, which made it attractive to users who wanted to encrypt files and send encrypted emails at no cost. The layers of security are also attractive and helped file encryption with PGP spread among security-conscious users – PGP uses both symmetric encryption and public key encryption, so users can send or receive messages from people they’re never met without exchanging private encryption keys.

Is PGP Still Used Today?

 PGP, OpenPGP, and GPG are all still in use today, and they continue to be secure methods to encrypt your data. PGP-compatible encryption remains relevant for file-based workflows, especially where organizations and trading partners need interoperable encryption, digital signatures, and automated key-based processes.

What's the Difference Between PGP and GPG?

Media
 
Text

GPG, or GnuPG, is a different implementation of the OpenPGP standard (more on that below), and a powerful alternative to Symantec’s official PGP software. Also known as the GNU Privacy Guard, GPG is useful in that it works well with non-GPG-based products and can open and decrypt files encrypted by PGP or OpenPGP.

TermWhat It Is
PGPOriginal encryption technology and product lineage
OpenPGPOpen standard for interoperable encryption, signatures, and keys
GPG/GnuPGFree software implementation of the OpenPGP standard

Keep reading: PGP vs. GPG: What’s the Difference?

PGP Solutions

Text

There are a number of PGP solutions available and which ones organizations choose to use depends on what encryption, privacy and security requirements are needed. Here are two popular PGP solutions supported by GoAnywhere:

  • OpenPGP: This standard of PGP encryption is open-source for public use. The term "OpenPGP" can be used to describe any program that supports the OpenPGP system. Open uses asymmetric (public key) cryptography and manages data authentication and non-repudiation through the ability to "sign" files via embedded digital signatures. This provides a high level of data protection, making PGP one of the most popular encryption methods used today.
  • GnuPG (GPG): GPG, also known as GNU Privacy Guard (GnuPG), is an implementation of the OpenPGP standard. It is an open-source option that can be used to open and decrypt files encrypted by PGP and/or OpenPGP. It also provides support for S/MIME and Secure Shell (SSH). GPG is popular as it supports multiple platforms.

Prior to GoAnywhere MFT, we had to manually download our deposit files from Wells Fargo's HTTPS server on a daily basis. Now with GoAnywhere, we have scheduled those files to be downloaded automatically, which it then imports into a database on our System i server. All of the manual steps were eliminated!

Barbara Bularzik, Monterey Mushrooms, Inc.

Using MFT for PGP Decryption and Encryption

Text

Desktop tools can support occasional manual encryption, but enterprise teams often need to encrypt, decrypt, sign, verify, and move files without user intervention. Some managed file transfer (MFT) tools, including GoAnywhere MFT, support OpenPGP. Using an MFT solution gives you the ability to leverage OpenPGP to:

  • Encrypt files with one or more Public Keys
  • Decrypt files with Private Keys
  • Sign files with Private Keys
  • Verify digital signatures in files using Public Keys
  • Generate full audit logs of all PGP encryption and decryption processes
  • Automate the entire process
  • Trigger encryption or decryption when files arrive in monitored folders
  • Schedule recurring PGP workflows for trading partner exchanges
  • Send alerts when encryption, decryption, or transfer processes fail
  • Transfer encrypted files through secure protocols after processing
  • Centralize PGP key management for automated workflows
     

Maintain the privacy and integrity of the data you exchange with external trading partners, clients, customers, and internal users when you use OpenPGP via MFT.

How to Open or Decrypt a PGP File

Media
 
Text

Opening or decrypting a PGP file is easy with GoAnywhere’s OpenPGP Studio. This free encryption solution lets you easily encrypt, decrypt, and sign files, as well as verify documents, to protect your sensitive files while complying with the OpenPGP standard. It uses a safer, dual-key (asymmetric) system to encrypt and decrypt information.

Just download and install PGP Studio, press F1 for help and you'll get all the help you need.

To jump right to how to get started on decrypting a file in OpenPGP Studio, check out this video.

Automation of PGP in GoAnywhere MFT

Media
Image
Illustration of 3 gears
Text
  • Automatically transfer files after they are encrypted with PGP
  • Retrieve OpenPGP files from other servers and decrypt in a workflow
  • Schedule OpenPGP processes to run at future dates and times
  • Integrate and connect with existing applications, programs and scripts with Cloud Connectors

Learn more about Automating OpenPGP > 

OpenPGP Key Management

Media
Image
GoAnywhere MFT Open PGP key manager
Text

A comprehensive OpenPGP Key Manager is provided in GoAnywhere MFT.

  • Intuitive browser-based interface
  • Create, import, export and view PGP keys
  • Receive email alerts when OpenPGP keys are about to expire
  • Role based permissions only allow authorized users to manage PGP keys

Manage OpenPGP Keys in GoAnywhere MFT > 

Multi-Platform

Text

GoAnywhere MFT can be installed to a variety of platforms to perform your OpenPGP encryption and decryption processes.

Image
Five of the platforms GoAnywhere works with: Windows, Apple, IBM i (iSeries), VMware, and RedHat

View all platforms >  

Cloud Integrations

Media
 
Text

GoAnywhere connects to popular web apps that businesses and their trading partners use. Cloud Connectors integrate with a variety of technologies and help to:

  • Automate your data, processes, and other tasks
  • Build reusable connectors to different technologies
  • Centralize your web service through GoAnywhere

Explore GoAnywhere's Cloud Connectors & Integrations >

Manually Encrypting a File with PGP

Text

If not applying automation to PGP encryption you can manually encrypt a message or file by following these steps:

  1. First, obtain your trading partner’s public key to encrypt the file. NOTE: This is not the private key that allows your recipient to decrypt the file.
  2. Once you’ve received the trading partner’s public key, you can import it to a key manager or vault. 
  3. Once that key is imported to the vault, you can create an encryption task or workflow that uses the recipient’s public key to protect the file. Signing helps the recipient verify the sender and detect unauthorized changes NOTE: Users may be required to sign the encrypted file with a private key to add an additional layer of security to the data.

This tutorial provides more extensive details.

Empower End Users to Encrypt Files Manually

Text

If you are looking for an easy way to empower an end user, not a GoAnywhere Administrator, to encrypt files manually, another option is to use GoAnywhere’s Secure Forms module. Within Secure Forms a user can select the PGP Public Key from a drop-down list, attach the file to encrypt the file. From there, simply press submit to encrypt it and then get a link to download and save the PGP file. This allows the user to distribute the file as needed, or in the form itself allow the use of SFTP, Secure Mail, or other options to deliver it after encryption. It also enables administrators to standardize encryption rules while giving approved end users a simpler self-service experience

 

 

Secure Your File Movement with GoAnywhere

Start a free 30-day trial and see if GoAnywhere is the right solution for your organization.

Get Started