Debian Sanctuary Project
Summary
Email Privacy
Debian Email Privacy Packages

This metapackage will install packages useful for browsing anonymously in Debian.

Description

For a better overview of the project's availability as a Debian package, each head row has a color code according to this scheme:

If you discover a project which looks like a good candidate for Debian Sanctuary to you, or if you have prepared an unofficial Debian package, please do not hesitate to send a description of that project to the Debian Sanctuary mailing list

Links to other tasks

Debian Sanctuary Email Privacy packages

Official Debian packages with high relevance

gnupg
GNU privacy guard - a free PGP replacement
Versions of package gnupg
ReleaseVersionArchitectures
bullseye-security2.2.27-2+deb11u2all
bookworm2.2.40-1.1+deb12u1all
forky2.4.8-3all
trixie2.4.7-21all
sid2.4.8-3all
bullseye2.2.27-2+deb11u2all
Debtags of package gnupg:
interfacecommandline
roleprogram
scopeutility
securityauthentication, cryptography, privacy
suitegnu
usechecking
works-withfile, text
Popcon: 93072 users (16837 upd.)*
Versions and Archs
License: DFSG free
Git

GnuPG is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC4880.

This package contains the full suite of GnuPG tools for cryptographic communications and data storage.

The package is enhanced by the following packages: paperkey
Screenshots of package gnupg
gnupg-agent
GNU privacy guard - cryptographic agent (dummy transitional package)
Versions of package gnupg-agent
ReleaseVersionArchitectures
trixie2.4.7-21all
bullseye-security2.2.27-2+deb11u2all
bookworm2.2.40-1.1+deb12u1all
sid2.4.8-3all
forky2.4.8-3all
bullseye2.2.27-2+deb11u2all
Debtags of package gnupg-agent:
interfacecommandline
networkclient
roleprogram
securitycryptography
suitegnu
works-withpim
Popcon: 4889 users (187 upd.)*
Versions and Archs
License: DFSG free
Git

GnuPG is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC4880.

This is a dummy transitional package; please use gpg-agent instead.

gnupg-pkcs11-scd
GnuPG smart-card daemon with PKCS#11 support
Maintainer: Thorsten Alteholz
Versions of package gnupg-pkcs11-scd
ReleaseVersionArchitectures
bullseye0.9.2-1amd64,arm64,armhf,i386
bookworm0.10.0-2amd64,arm64,armel,armhf,i386,mips64el,mipsel,ppc64el,s390x
trixie0.10.0-5amd64,arm64,armel,armhf,i386,ppc64el,riscv64,s390x
forky0.10.0-5amd64,arm64,armhf,i386,ppc64el,riscv64,s390x
sid0.10.0-5amd64,arm64,armel,armhf,i386,mips64el,ppc64el,riscv64,s390x
upstream0.11.0
Popcon: 13 users (7 upd.)*
Newer upstream!
License: DFSG free
Git

gnupg-pkcs11-scd is a drop-in replacement for the smart-card daemon (scd) shipped with GnuPG. The daemon interfaces to smart-cards by using RSA Security Inc. PKCS#11 Cryptographic Token Interface (Cryptoki).

gnupg2
GNU privacy guard - a free PGP replacement (dummy transitional package)
Versions of package gnupg2
ReleaseVersionArchitectures
sid2.4.8-3all
bookworm2.2.40-1.1+deb12u1all
bullseye2.2.27-2+deb11u2all
trixie2.4.7-21all
bullseye-security2.2.27-2+deb11u2all
forky2.4.8-3all
Debtags of package gnupg2:
interfacecommandline
roleprogram
scopeutility
securitycryptography
suitegnu
useconverting
Popcon: 32757 users (1143 upd.)*
Versions and Archs
License: DFSG free
Git

GnuPG is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC4880.

This is a dummy transitional package that provides symlinks from gpg2 to gpg.

kleopatra
Certificate Manager and Unified Crypto GUI
Versions of package kleopatra
ReleaseVersionArchitectures
sid24.12.3-2amd64,arm64,armel,armhf,i386,mips64el,ppc64el,riscv64,s390x
bullseye20.08.3-1amd64,arm64,armhf,i386
bookworm22.12.3-1amd64,arm64,armel,armhf,i386,mips64el,mipsel,ppc64el,s390x
trixie24.12.3-1amd64,arm64,armel,armhf,i386,ppc64el,riscv64,s390x
forky24.12.3-2amd64,arm64,armhf,i386,ppc64el,riscv64,s390x
upstream25.08.2
Debtags of package kleopatra:
interfacex11
networkclient
roleprogram
securityauthentication
suitekde
uitoolkitqt
works-withdb, pim
x11application
Popcon: 383 users (306 upd.)*
Newer upstream!
License: DFSG free
Git

Kleopatra is a certificate manager and a universal crypto GUI. It supports managing X.509 and OpenPGP certificates in the GpgSM keybox and retrieving certificates from LDAP servers.

monkeysphere
leverage the OpenPGP web of trust for SSH and TLS authentication
Versions of package monkeysphere
ReleaseVersionArchitectures
bullseye0.43-3.1all
experimental0.44-1all
Debtags of package monkeysphere:
securityauthentication
Popcon: 16 users (0 upd.)*
Versions and Archs
License: DFSG free
Git

SSH key-based authentication is tried-and-true, but it lacks a true Public Key Infrastructure for key certification, revocation and expiration. Monkeysphere is a framework that uses the OpenPGP web of trust for these PKI functions. It can be used in both directions: for users to get validated host keys, and for hosts to authenticate users. Current monkeysphere SSH tools are designed to integrate with the OpenSSH implementation of the Secure Shell protocol.

Monkeysphere can also be used by a validation agent to validate TLS connections (e.g. https).

parcimonie
privacy-friendly helper to refresh a GnuPG keyring
Versions of package parcimonie
ReleaseVersionArchitectures
bullseye0.12.0-2all
bookworm0.12.0-2all
sid0.12.0-2all
Debtags of package parcimonie:
roleprogram
securitycryptography
uitoolkitgtk
Popcon: 46 users (1 upd.)*
Versions and Archs
License: DFSG free
Git

parcimonie is a daemon that slowly refreshes a gpg public keyring from a keyserver.

It refreshes one OpenPGP key at a time; between every key update parcimonie sleeps a random amount of time, long enough for the previously used Tor circuit to expire.

This process is meant to make it hard for an attacker to correlate the multiple performed key update operations.

See the included design document to learn more about the threat and risk models parcimonie attempts to help coping with.

XDG-compliant desktop environments automatically start parcimonie.

Screenshots of package parcimonie
seahorse-nautilus
Nautilus extension for Seahorse integration
Versions of package seahorse-nautilus
ReleaseVersionArchitectures
trixie3.11.92+git20230129.d59dc92f-2amd64,arm64,armel,armhf,i386,ppc64el,riscv64,s390x
bullseye3.11.92-4amd64,arm64,armhf,i386
bookworm3.11.92+git20230129.d59dc92f-1amd64,arm64,armel,armhf,i386,mips64el,mipsel,ppc64el,s390x
forky3.11.92+git20230129.d59dc92f-2amd64,arm64,armhf,i386,ppc64el,riscv64,s390x
sid3.11.92+git20230129.d59dc92f-2amd64,arm64,armel,armhf,i386,mips64el,ppc64el,riscv64,s390x
Debtags of package seahorse-nautilus:
uitoolkitgtk
Popcon: 82 users (19 upd.)*
Versions and Archs
License: DFSG free
Git

Seahorse nautilus is an extension for nautilus which allows encryption and decryption of OpenPGP files using GnuPG - the GNU Privacy Guard program.

Screenshots of package seahorse-nautilus
signing-party
Various OpenPGP related tools
Maintainer: Guilhem Moulin
Versions of package signing-party
ReleaseVersionArchitectures
bullseye2.11-1amd64,arm64,armhf,i386
sid2.12-1amd64,arm64,armel,armhf,i386,mips64el,ppc64el,riscv64,s390x
forky2.12-1amd64,arm64,armhf,i386,ppc64el,riscv64,s390x
trixie2.12-1amd64,arm64,armel,armhf,i386,ppc64el,riscv64,s390x
bookworm2.11-1amd64,arm64,armel,armhf,i386,mips64el,mipsel,ppc64el,s390x
Debtags of package signing-party:
interfacecommandline
roleprogram
scopeutility
securitycryptography
works-withmail, text
works-with-formatpostscript
Popcon: 48 users (21 upd.)*
Versions and Archs
License: DFSG free
Git

signing-party is a collection for all kinds of PGP/GnuPG related things, including tools for signing keys, keyring analysis, and party preparation.

  • caff: CA - Fire and Forget signs and mails a key
  • pgp-clean: removes all non-self signatures from key
  • pgp-fixkey: removes broken packets from keys
  • gpg-mailkeys: simply mail out a signed key to its owner
  • gpg-key2ps: generate PostScript file with fingerprint paper slips
  • gpgdir: recursive directory encryption tool
  • gpglist: show who signed which of your UIDs
  • gpgsigs: annotates list of GnuPG keys with already done signatures
  • gpgparticipants: create list of party participants for the organiser
  • gpgwrap: a passphrase wrapper
  • keyanalyze: minimum signing distance (MSD) analysis on keyrings
  • keylookup: ncurses wrapper around gpg --search
  • sig2dot: converts a list of GnuPG signatures to a .dot file
  • springgraph: creates a graph from a .dot file
  • keyart: creates a random ASCII art of a PGP key file
  • gpg-key2latex: generate LaTeX file with fingerprint paper slips
*Popularitycontest results: number of people who use this package regularly (number of people who upgraded this package recently) out of 268365