LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-08-2013, 03:59 PM   #1
mysmys
LQ Newbie
 
Registered: Jun 2013
Posts: 2

Rep: Reputation: Disabled
Plan for DIY secure email


Pardon me, but while proficient in many areas of computer and electronics technology, I am new to linux. Perhaps this thread belongs in the newbie section, but it is regarding security, so here it is.

I am working with Ubuntu server 12.04 and excited about learning this new platform and getting away from the dark side of non-open source software. So, I am working on two goals at once - learn and run linux (server) and create a secure and non-traceable portal for general email communications. The latter comes about after a long, on-going discussion amongst members of a business group who wish to discuss both business and items of personal nature via email. Now, with the recent revelation of governmental intrusion into our means of electronic communication, I am further inspired to continue with this project and think it should be a consideration for everyone.

There are certainly some commercial services that might offer this, but I would like the satisfaction and possible added protection of building something myself.

PGP using common, public email providers certainly offers message encryption to a satisfactory level. Messages may persist in the cloud somewhere and be publicly discoverable at some level, but are probably uncrackable most reasonable means. However there are certainly trails leading to the senders and recipients of such messages.

My goals would be:
1) encrypt all email info (message and recipients)
2) info in #1 above stored in encrypted form on the server
3) eliminate any unauthorized or forced access to the encrypted message on the email server
4) further encryption of email from the clients to the server via VPN or SSL obfuscate the data stream between client and server as to even the type of protocol (email, for ex.)

So my thoughts are:
1) Build up a linux server with open source email components - qmail seems to be a good candidate for the MTA. Have clients use PGP.
2) Use whole computer or disk encryption method to thwart efforts to benefit from access to the physical or virtual computer.
3) Use SSL tunnel between client and server
4) Add further hardening of the linux server and network via either hardware of OS configuration (iptables or other)

This would seem to offer all the goals enumerated above and perhaps not be too much of a technical challenge.

This
http://www.sans.org/reading_room/whi...il-server_1372
is a reference I got from linuxquestions.org and seems to be good except that it may be a bit dated (2004).

Thoughts?
 
Old 06-11-2013, 05:06 AM   #2
chrism01
LQ Guru
 
Registered: Aug 2004
Location: Sydney
Distribution: Rocky 9.2
Posts: 18,359

Rep: Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751
For the client end, have you looked at Enigmail http://www.enigmail.net/home/index.php?

I would say that ALL the technologies mentioned in the SANS link have moved on significantly.
You could use it for a suggestions of things to consider, but I'd seriously research the current state of the art before doing anything.

You basically have 3 things to consider:
a) encryption at rest eg pgp, gpg
b) encrypted comms eg ssh tunnel, ssl tunnel, vpn (eg IPsec/IKE)
c) traffic analysis ie shielding the info of who is talking to whom.
In re c), I've never used it, but the Tor network is designed to solve that problem ie make it very hard to see who is talking to whom.
https://en.wikipedia.org/wiki/Tor_%2...ity_network%29
 
1 members found this post helpful.
Old 06-13-2013, 12:23 PM   #3
linosaurusroot
Member
 
Registered: Oct 2012
Distribution: OpenSuSE,RHEL,Fedora,OpenBSD
Posts: 982
Blog Entries: 2

Rep: Reputation: 244Reputation: 244Reputation: 244
mixmaster (and mixminion) is an anonymous remailer tool specifically for anonymous mail as opposed to other types of traffic.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Details on Ubuntu's UEFI secure boot plan LXer Syndicated Linux News 0 06-22-2012 02:01 PM
Is this routing plan secure? marcusshirley Linux - Security 2 08-24-2006 02:45 PM
Is this routing plan secure? marcusshirley Linux - Newbie 2 08-22-2006 01:41 PM
Secure email (SSL vs. secure authentication) jrdioko Linux - Newbie 2 11-28-2004 01:39 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:09 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration