Debian Sanctuary Project
Summary
Email Privacy
Debian Email Privacy Packages

This metapackage will install packages useful for browsing anonymously in Debian.

Description

For a better overview of the project's availability as a Debian package, each head row has a color code according to this scheme:

If you discover a project which looks like a good candidate for Debian Sanctuary to you, or if you have prepared an unofficial Debian package, please do not hesitate to send a description of that project to the Debian Sanctuary mailing list

Links to other tasks

Debian Sanctuary Email Privacy packages

Official Debian packages with high relevance

gnupg
GNU privacy guard - a free PGP replacement
Versions of package gnupg
ReleaseVersionArchitectures
bullseye-security2.2.27-2+deb11u2all
bullseye2.2.27-2+deb11u2all
experimental2.4.5-1all
buster-backports2.2.27-2~bpo10+1all
sid2.2.40-3all
stretch-backports-sloppy2.2.20-1~bpo9+1all
stretch2.1.18-8~deb9u4amd64,arm64,armel,armhf,i386,mips,mips64el,mipsel,ppc64el,s390x
buster-security2.2.12-1+deb10u2all
jessie1.4.18-7+deb8u5amd64,armel,armhf,i386
jessie-security1.4.18-7+deb8u5amd64,armel,armhf,i386
buster2.2.12-1+deb10u2all
trixie2.2.40-1.1all
bookworm2.2.40-1.1all
stretch-backports2.2.12-1+deb10u1~bpo9+1all
stretch-security2.1.18-8~deb9u2amd64,arm64,armel,armhf,i386
upstream2.2.43
Debtags of package gnupg:
interfacecommandline
roleprogram
scopeutility
securityauthentication, cryptography, privacy
suitegnu
usechecking
works-withfile, text
Popcon: 130308 users (12786 upd.)*
Newer upstream!
License: DFSG free
Git

GnuPG is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC4880.

This package contains the full suite of GnuPG tools for cryptographic communications and data storage.

The package is enhanced by the following packages: dirmngr gnupg-l10n paperkey
Screenshots of package gnupg
gnupg-agent
GNU privacy guard - cryptographic agent (dummy transitional package)
Versions of package gnupg-agent
ReleaseVersionArchitectures
buster-security2.2.12-1+deb10u2all
stretch-backports2.2.12-1+deb10u1~bpo9+1all
buster2.2.12-1+deb10u2all
sid2.2.40-3all
trixie2.2.40-1.1all
bookworm2.2.40-1.1all
bullseye-security2.2.27-2+deb11u2all
bullseye2.2.27-2+deb11u2all
buster-backports2.2.27-2~bpo10+1all
stretch-backports-sloppy2.2.20-1~bpo9+1all
jessie2.0.26-6+deb8u2amd64,armel,armhf,i386
experimental2.4.5-1all
jessie-security2.0.26-6+deb8u2amd64,armel,armhf,i386
stretch-security2.1.18-8~deb9u2amd64,arm64,armel,armhf,i386
stretch2.1.18-8~deb9u4amd64,arm64,armel,armhf,i386,mips,mips64el,mipsel,ppc64el,s390x
upstream2.2.43
Debtags of package gnupg-agent:
interfacecommandline
networkclient
roleprogram
securitycryptography
suitegnu
works-withpim
Popcon: 8037 users (88 upd.)*
Newer upstream!
License: DFSG free
Git

GnuPG is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC4880.

This is a dummy transitional package; please use gpg-agent instead.

gnupg-curl
??? missing short description for package gnupg-curl :-(
Versions of package gnupg-curl
ReleaseVersionArchitectures
jessie1.4.18-7+deb8u5amd64,armel,armhf,i386
jessie-security1.4.18-7+deb8u5amd64,armel,armhf,i386
Debtags of package gnupg-curl:
interfacecommandline
networkclient
roleplugin, program
scopeutility
securityauthentication, cryptography
suitegnu
usechecking
works-withfile, text
Popcon: 84 users (1 upd.)*
Versions and Archs
License: DFSG free
Git
gnupg-pkcs11-scd
GnuPG smart-card daemon with PKCS#11 support
Maintainer: Thorsten Alteholz
Versions of package gnupg-pkcs11-scd
ReleaseVersionArchitectures
sid0.10.0-3amd64,arm64,armel,armhf,i386,mips64el,ppc64el,riscv64,s390x
jessie0.7.3-1amd64,armel,armhf,i386
stretch0.7.3-3amd64,arm64,armel,armhf,i386,mips,mips64el,mipsel,ppc64el,s390x
bullseye0.9.2-1amd64,arm64,armel,armhf,i386,mips64el,mipsel,ppc64el,s390x
bookworm0.10.0-2amd64,arm64,armel,armhf,i386,mips64el,mipsel,ppc64el,s390x
buster0.9.2-1amd64,arm64,armhf,i386
Popcon: 12 users (5 upd.)*
Versions and Archs
License: DFSG free
Git

gnupg-pkcs11-scd is a drop-in replacement for the smart-card daemon (scd) shipped with GnuPG. The daemon interfaces to smart-cards by using RSA Security Inc. PKCS#11 Cryptographic Token Interface (Cryptoki).

gnupg2
GNU privacy guard - a free PGP replacement (dummy transitional package)
Versions of package gnupg2
ReleaseVersionArchitectures
buster-security2.2.12-1+deb10u2all
jessie2.0.26-6+deb8u2amd64,armel,armhf,i386
jessie-security2.0.26-6+deb8u2amd64,armel,armhf,i386
stretch-security2.1.18-8~deb9u2all
stretch2.1.18-8~deb9u4all
stretch-backports2.2.12-1+deb10u1~bpo9+1all
buster2.2.12-1+deb10u2all
stretch-backports-sloppy2.2.20-1~bpo9+1all
buster-backports2.2.27-2~bpo10+1all
bullseye2.2.27-2+deb11u2all
bullseye-security2.2.27-2+deb11u2all
bookworm2.2.40-1.1all
trixie2.2.40-1.1all
sid2.2.40-3all
experimental2.4.5-1all
upstream2.2.43
Debtags of package gnupg2:
interfacecommandline
roleprogram
scopeutility
securitycryptography
suitegnu
useconverting
Popcon: 34716 users (661 upd.)*
Newer upstream!
License: DFSG free
Git

GnuPG is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC4880.

This is a dummy transitional package that provides symlinks from gpg2 to gpg.

kleopatra
Certificate Manager and Unified Crypto GUI
Versions of package kleopatra
ReleaseVersionArchitectures
bookworm22.12.3-1amd64,arm64,armel,armhf,i386,mips64el,mipsel,ppc64el,s390x
jessie-security4.14.1-1+deb8u2amd64,armel,armhf,i386
bullseye20.08.3-1amd64,arm64,armel,armhf,i386,mips64el,mipsel,ppc64el,s390x
jessie4.14.1-1+deb8u1amd64,armel,armhf,i386
trixie22.12.3-2amd64,arm64,armel,armhf,i386,mips64el,ppc64el,s390x
sid22.12.3-2amd64,arm64,armel,armhf,i386,mips64el,ppc64el,riscv64,s390x
buster18.08.3-1amd64,arm64,armhf,i386
stretch16.04.2-2amd64,arm64,armel,armhf,i386,mips,mips64el,mipsel,ppc64el,s390x
upstream24.02.2
Debtags of package kleopatra:
interfacex11
networkclient
roleprogram
securityauthentication
suitekde
uitoolkitqt
works-withdb, pim
x11application
Popcon: 363 users (252 upd.)*
Newer upstream!
License: DFSG free
Git

Kleopatra is a certificate manager and a universal crypto GUI. It supports managing X.509 and OpenPGP certificates in the GpgSM keybox and retrieving certificates from LDAP servers.

monkeysign
OpenPGP key signing and exchange for humans
Maintainer: Antoine Beaupré
Versions of package monkeysign
ReleaseVersionArchitectures
jessie2.0.2all
stretch2.2.3+deb9u1all
buster2.2.4all
Debtags of package monkeysign:
hardwarecamera
interfacetext-mode, x11
mailsmtp
networkclient
roleprogram
scopeapplication
securityauthentication, cryptography
uitoolkitgtk
usechecking
works-withmail
x11application
Popcon: 0 users (0 upd.)*
Versions and Archs
License: DFSG free
Git

monkeysign is a tool to overhaul the OpenPGP keysigning experience and bring it closer to something that most primates can understand.

The project makes use of cheap digital cameras and the type of bar code known as a QRcode to provide a human-friendly yet still-secure keysigning experience.

No more reciting tedious strings of hexadecimal characters. And, you can build a little rogue's gallery of the people that you have met and exchanged keys with!

Monkeysign is the commandline signing software, a caff replacement. Monkeyscan is the graphical user interface that scans qrcodes.

monkeysphere
leverage the OpenPGP web of trust for SSH and TLS authentication
Versions of package monkeysphere
ReleaseVersionArchitectures
sid0.43-3.1all
bullseye0.43-3.1all
buster0.43-3all
stretch-backports0.43-2~bpo9+1all
stretch0.41-1+deb9u1all
jessie0.37-2all
experimental0.44-1all
Debtags of package monkeysphere:
securityauthentication
Popcon: 28 users (2 upd.)*
Versions and Archs
License: DFSG free
Git

SSH key-based authentication is tried-and-true, but it lacks a true Public Key Infrastructure for key certification, revocation and expiration. Monkeysphere is a framework that uses the OpenPGP web of trust for these PKI functions. It can be used in both directions: for users to get validated host keys, and for hosts to authenticate users. Current monkeysphere SSH tools are designed to integrate with the OpenSSH implementation of the Secure Shell protocol.

Monkeysphere can also be used by a validation agent to validate TLS connections (e.g. https).

parcimonie
privacy-friendly helper to refresh a GnuPG keyring
Versions of package parcimonie
ReleaseVersionArchitectures
jessie0.8.4-1all
buster0.11.0-1all
bullseye0.12.0-2all
bookworm0.12.0-2all
trixie0.12.0-2all
sid0.12.0-2all
stretch0.10.2-4all
Debtags of package parcimonie:
roleprogram
securitycryptography
uitoolkitgtk
Popcon: 70 users (1 upd.)*
Versions and Archs
License: DFSG free
Git

parcimonie is a daemon that slowly refreshes a gpg public keyring from a keyserver.

It refreshes one OpenPGP key at a time; between every key update parcimonie sleeps a random amount of time, long enough for the previously used Tor circuit to expire.

This process is meant to make it hard for an attacker to correlate the multiple performed key update operations.

See the included design document to learn more about the threat and risk models parcimonie attempts to help coping with.

XDG-compliant desktop environments automatically start parcimonie.

Screenshots of package parcimonie
seahorse-nautilus
Nautilus extension for Seahorse integration
Versions of package seahorse-nautilus
ReleaseVersionArchitectures
jessie3.11.92-1amd64,armel,armhf,i386
stretch3.11.92-1.1amd64,arm64,armel,armhf,i386,mips,mips64el,mipsel,ppc64el,s390x
buster3.11.92-2amd64,arm64,armhf,i386
bullseye3.11.92-4amd64,arm64,armel,armhf,i386,mips64el,mipsel,ppc64el,s390x
bookworm3.11.92+git20230129.d59dc92f-1amd64,arm64,armel,armhf,i386,mips64el,mipsel,ppc64el,s390x
trixie3.11.92+git20230129.d59dc92f-1amd64,arm64,armel,armhf,i386,mips64el,ppc64el,s390x
sid3.11.92+git20230129.d59dc92f-1amd64,arm64,armel,armhf,i386,mips64el,ppc64el,riscv64,s390x
Debtags of package seahorse-nautilus:
uitoolkitgtk
Popcon: 90 users (12 upd.)*
Versions and Archs
License: DFSG free
Git

Seahorse nautilus is an extension for nautilus which allows encryption and decryption of OpenPGP files using GnuPG - the GNU Privacy Guard program.

Screenshots of package seahorse-nautilus
signing-party
Various OpenPGP related tools
Maintainer: Guilhem Moulin
Versions of package signing-party
ReleaseVersionArchitectures
jessie1.1.10-3amd64,armel,armhf,i386
jessie-security1.1.10-3+deb8u1amd64,armel,armhf,i386
stretch2.5-1+deb9u1amd64,arm64,armel,armhf,i386,mips,mips64el,mipsel,ppc64el,s390x
buster2.10-2amd64,arm64,armhf,i386
bullseye2.11-1amd64,arm64,armel,armhf,i386,mips64el,mipsel,ppc64el,s390x
bookworm2.11-1amd64,arm64,armel,armhf,i386,mips64el,mipsel,ppc64el,s390x
trixie2.11-1amd64,arm64,armel,armhf,i386,mips64el,ppc64el,s390x
sid2.11-1amd64,arm64,armel,armhf,i386,mips64el,ppc64el,riscv64,s390x
Debtags of package signing-party:
interfacecommandline
roleprogram
scopeutility
securitycryptography
works-withmail, text
works-with-formatpostscript
Popcon: 56 users (11 upd.)*
Versions and Archs
License: DFSG free
Git

signing-party is a collection for all kinds of PGP/GnuPG related things, including tools for signing keys, keyring analysis, and party preparation.

  • caff: CA - Fire and Forget signs and mails a key
  • pgp-clean: removes all non-self signatures from key
  • pgp-fixkey: removes broken packets from keys
  • gpg-mailkeys: simply mail out a signed key to its owner
  • gpg-key2ps: generate PostScript file with fingerprint paper slips
  • gpgdir: recursive directory encryption tool
  • gpglist: show who signed which of your UIDs
  • gpgsigs: annotates list of GnuPG keys with already done signatures
  • gpgparticipants: create list of party participants for the organiser
  • gpgwrap: a passphrase wrapper
  • keyanalyze: minimum signing distance (MSD) analysis on keyrings
  • keylookup: ncurses wrapper around gpg --search
  • sig2dot: converts a list of GnuPG signatures to a .dot file
  • springgraph: creates a graph from a .dot file
  • keyart: creates a random ASCII art of a PGP key file
  • gpg-key2latex: generate LaTeX file with fingerprint paper slips
*Popularitycontest results: number of people who use this package regularly (number of people who upgraded this package recently) out of 236283