PGP decrypt and verify (2024)

PGP decrypt and verify

Contents

Overview
Configuration

Overview

You can use the PGP Decrypt and Verify filter to decrypt a message encrypted with Pretty Good Privacy (PGP). This filter decrypts an incoming message using the specified PGP private key, and creates a new message body using the specified content type. The decrypted message can be processed by API Gateway, and then encrypted again using the PGP Encrypt and Sign filter.

An example use case for this filter would be when files are sent to API Gateway over Secure Shell File Transfer Protocol (SFTP) in PGP-encrypted format. API Gateway can use the PGP Decrypt and Verify filter to decrypt the message, and then use threat detection filters to perform virus scanning. The clean files can be PGP-encrypted again using the PGP Encrypt and Sign filter before being sent over SFTP to their target destination. For more details, see the PGP encrypt and sign filter.

You can also use the PGP Decrypt and Verify filter to to verify signed messages passing through the API Gateway pipeline. Signed messages received by API Gateway can be verified by validating the signature using the public PGP key of the message signer.

PGP decrypt and verify (1) Note

PGP decryption and verification require two different keys: your own private key for decryption, and the sender's public key for verification.

Complete the following fields to configure this filter:

Name:

Enter an appropriate name for this filter.

Decrypt:

Select whether to use this filter to PGP decrypt an incoming message with a private key.

PGP Private Key to be retrieved from one of the following locations:

If you selected the Decrypt option, select the location of the private key from one of the following options:

  • PGP Key Pair list:

    Click the browse button on the right, and select a PGP key pair configured in the certificate store. If no PGP key pairs have already been configured, right-click PGP Key Pairs, and select Add PGP Key. For details on configuring PGP key pairs, see the section called “Configure PGP key pairs”.

  • Alias:

    Enter the alias name used to look up the PGP key in the certificate store (for example, My PGP Test Key). Alternatively, you can enter a selector expression with the name of a message attribute that contains the alias. The value of the selector is expanded at runtime (for example, ${my.pgp.test.key.alias}).

  • Message attribute:

    Enter a selector expression with the name of the message attribute that contains the key. The value of the selector is expanded at runtime (for example, ${my.pgp.test.private.key}).

For more details on selectors, see Select configuration values at runtime.

Verify:

Select whether to use this filter to verify an incoming signed message with the public key used to sign the message.

Verification Key Location (Public Key):

If you selected the Verify option, select the location of the public key from one of the following options:

  • PGP Key Pair list:

    Click the browse button on the right, and select a PGP key pair configured in the certificate store. If no PGP key pairs have already been configured, right-click PGP Key Pairs, and select Add PGP Key. For details on configuring PGP key pairs, see the section called “Configure PGP key pairs”.

  • Alias:

    Enter the alias name used to look up the PGP key in the certificate store (for example, My PGP Test Key). Alternatively, you can enter a selector expression with the name of a message attribute that contains the alias. The value of the selector is expanded at runtime (for example, ${my.pgp.test.key.alias}).

  • Message attribute:

    Enter a selector expression with the name of the message attribute that contains the key. The value of the selector is expanded at runtime (for example, ${my.pgp.test.public.key}).

For more details on selectors, see Select configuration values at runtime.

Signing Method:

If you selected to verify but not decrypt the incoming message, select a signing method from one of the following options:

  • Compressed:

    Verifies a compressed signature. Because the message is contained in the signature, this signature is used in place of the message. This is the default.

  • Clear signed:

    In a clear signed message, the message is intact with a signature attached beneath the clear message text. Verifying this message verifies the sender and the message integrity.

  • Detached signature (MIME):

    Verifies a multipart MIME document where the message is in clear text and the signature is attached as a MIME part.

Decrypt and Verify Method:

If you selected to decrypt and verify the incoming message, select the decrypt and verify method from one of the following options:

  • Decrypt and Verify in One Pass:

    Decrypts and verifies the message in a single pass. This is the default. API Gateway decrypts the message while reading the data packet, and continues on sequentially when it reaches the signature packet.

  • Decrypt and Verify in Two Passes:

    Decrypts the message in the first pass, and then verifies the signature in the second pass. Use this option when the message has been encrypted and signed in two passes.

Content type:

Enter the Content-Type of the unencrypted message data. Defaults to application/octet-stream.

Prev Up Next
Home
PGP decrypt and verify (2024)
Top Articles
Trading Blog: Expert Insights & Proven Strategies
Forex Spread: Was ist der Trading Spread beim Forex Handel?
Fat Hog Prices Today
Brady Hughes Justified
Login Page
Coverage of the introduction of the Water (Special Measures) Bill
Hawkeye 2021 123Movies
RuneScape guide: Capsarius soul farming made easy
The Best English Movie Theaters In Germany [Ultimate Guide]
King Fields Mortuary
Nieuwe en jong gebruikte campers
LA Times Studios Partners With ABC News on Randall Emmett Doc Amid #Scandoval Controversy
What Does Dwb Mean In Instagram
Cranberry sauce, canned, sweetened, 1 slice (1/2" thick, approx 8 slices per can) - Health Encyclopedia
4Chan Louisville
Taylor Swift Seating Chart Nashville
Nj Scratch Off Remaining Prizes
Busted Newspaper S Randolph County Dirt The Press As Pawns
Walmart End Table Lamps
Craigslist Edmond Oklahoma
Testberichte zu E-Bikes & Fahrrädern von PROPHETE.
UPS Store #5038, The
MLB power rankings: Red-hot Chicago Cubs power into September, NL wild-card race
8005607994
SN100C, An Australia Trademark of Nihon Superior Co., Ltd.. Application Number: 2480607 :: Trademark Elite Trademarks
Bocca Richboro
Sound Of Freedom Showtimes Near Movie Tavern Brookfield Square
Jersey Shore Subreddit
Uncovering the Enigmatic Trish Stratus: From Net Worth to Personal Life
Smayperu
Que Si Que Si Que No Que No Lyrics
Nacogdoches, Texas: Step Back in Time in Texas' Oldest Town
Tendermeetup Login
Dreammarriage.com Login
Dynavax Technologies Corp (DVAX)
Frcp 47
PruittHealth hiring Certified Nursing Assistant - Third Shift in Augusta, GA | LinkedIn
Let's co-sleep on it: How I became the mom I swore I'd never be
Armageddon Time Showtimes Near Cmx Daytona 12
Guy Ritchie's The Covenant Showtimes Near Grand Theatres - Bismarck
Top 1,000 Girl Names for Your Baby Girl in 2024 | Pampers
9:00 A.m. Cdt
Sandra Sancc
Zipformsonline Plus Login
Myra's Floral Princeton Wv
Windy Bee Favor
Motorcycle For Sale In Deep East Texas By Owner
Wera13X
Morgan State University Receives $20.9 Million NIH/NIMHD Grant to Expand Groundbreaking Research on Urban Health Disparities
All Obituaries | Roberts Funeral Home | Logan OH funeral home and cremation
Room For Easels And Canvas Crossword Clue
Latest Posts
Article information

Author: Terrell Hackett

Last Updated:

Views: 5579

Rating: 4.1 / 5 (52 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Terrell Hackett

Birthday: 1992-03-17

Address: Suite 453 459 Gibson Squares, East Adriane, AK 71925-5692

Phone: +21811810803470

Job: Chief Representative

Hobby: Board games, Rock climbing, Ghost hunting, Origami, Kabaddi, Mushroom hunting, Gaming

Introduction: My name is Terrell Hackett, I am a gleaming, brainy, courageous, helpful, healthy, cooperative, graceful person who loves writing and wants to share my knowledge and understanding with you.