



                             Decrypt Mail Utility
 
                              -  User's Manual  -
                              

                              Version 2.0.f beta




Contents
========

    Overview
    Decrypt's Features
    Installation
    Files
    Configuring Decrypt
    Decrypting Your Mail
        Method One
        Method Two
    Notes
    Securing the INI File
    Advanced Features
        File Wiping
        Output and Input Files
        Workpath
        RAMdrives
        Prompting
        Prior Blocks
    Command Line
    Attachments
    Multi-Part FixedSize Messages
    Importing and Exporting Messages - Agent, Netscape, Eudora



Overview
========

    The Decrypt Utility provides for automatic decryption of mail from nym
    accounts, including all layers of conventional and public-key encryption.
    Mail messages are saved to a file (or multiple files), and passphrases are
    entered in DEC.INI.  Decrypt then decrypts the mail and writes the plain
    text messages to the output text file, nornmally dec.txt.
    
    Decrypt v2 will decrypt and save PGP, UUEncoded, and MIME binary attachments
    to a default attachment directory, and will automatically assemble and
    decrypt multi-part fixedsize messages.  In addition, Decrypt can be
    configured to automatically export decrypted messages to Agent, Netscape,
    and Eudora.

    Decrypt is suitable for use in DOS and Windows, and includes a Windows95
    installation program.  Additionally, the remailer utility programs Potato
    and Jack B. Nymble can automatically export passphrases to DEC.INI.


Decrypt's Features
==================

    Support for automatic decryption of mail from nym reply blocks
        Multiple conventional decryption
        Secret key decryption
        Message decryption
        Attachment decryption
    Customizable INI file
    Optional encryption of passphrases (Secure Mode)
    
    Control over INI location (for multiple installations)
    Control over workpath used
    Control over command used to del/wipe files
    
    Attachments optionally decrypted/decoded to default attachment directory
    
    Support for both batches of input files and one file containing multiple        
        messages
    Automatic assembly and decryption of multi-part "fixedsize" messages    

    Import/Export of messages directly to Agent, Netscape, and Eudora
    

Installation
============

    Note:  If you install Potato or Jack B. Nymble (v0.9.c or later), this
    program is installed automatically.
    Otherwise:

    Windows95:
    Unzip the files to a temporary directory using WinZip.

    Run Install.bat.  This will create the directory "c:\Dec", will copy
    files, and will add shortcuts to your Start Menu.  (You may also use
    Install.bat to reinstall over a previous copy.  Your existing dec.ini file
    will be renamed to dec.old.)

    If you wish to install to a different directory, or if your windows
    directory is not c:\windows, you can specify these on the command line:
        install [programdirectory windowsdirectory]

    For example:
        install d:\Decrypt c:\win

    would install the program in d:\Decrypt and add shortcuts to Windows located
    in c:\win.  If you specify one you must specify both. NOTE: If you use this
    option will need to edit the shortcut properties after installation,
    entering the new directory and workpath.

    DOS or Win3.1:
    Unzip the files to a directory of your choice.  They may be located in the
    same directory as Potato, in a subdirectory such as c:\Pot\Dec, or in a
    separate directory such as c:\Dec.
    If using Windows, create a program item to dec.exe.

   
Files
=====

    The Decrypt Utility consists of three required files:
        dec.exe
        dec.ini
        udec.exe    (Required for UUE and MIME decoding only)

    From wherever it is run, dec.exe must be able to find dec.ini (and
    udec.exe).  The easiest way to insure this is to change to the directory
    containing these files and run dec.exe.

    This version of Decrypt also includes the following files:

        Decrypt.txt     This help file.
        dec.bak         A spare copy of dec.ini
        Install.bat     Windows95 installation program
        *.pif, *.lnk    Windows95 shortcuts
        zapfile.com     A secure file-wiping utility.

    Additionally, Decrypt may create these files when running:

        dec_*.tmp       Temporary files which should be deleted automatically.
        dec.pgp         Secured version of dec.ini
        dec.txt         The default output file.


Configuring Decrypt
===================

    Decrypt is designed to automatically decrypt your nym mail, however many
    times required, with all the passphrases and key passphrases you use.  It
    can handle messages from several accounts simultaneously.

    The first step in using the program is to add all your passphrases to the
    INI file.  Load dec.ini into any plaintext editor (such as Notepad).

    Conventional passphrases should be grouped by the reply-block they belong
    to.  For example:

    ---block
    Your_Passphrase_3
    Your_Passphrase_2
    Your_Passphrase_1
    
    ---block
    Your_Passphrase_6
    Your_Passphrase_5
    Your_Passphrase_4
    ---endblock
    
    This shows the passphrases for two reply-blocks.  Note that it doesn't
    matter which block belongs to which account.
    
    For optimum efficiency, passphrases should be listed in the order they will
    be used.

    Add all the conventional phrases for all your accounts.  If you do not use
    conventional encryption in your reply block(s), do not enter any "---block"
    sets.

    Although decrypt will accept spaces in any passphrase, using such
    passphrases for conventional encryption is not recommended, because of the
    variation in the way remailers handle spaces.



    Next enter the secret-key passphrases for all your nym keys.  Ideally,
    provide the KeyID for the key, so that Decrypt knows which passphrase to
    use.  (To find the KeyID for your key, type PGP -kv youruserid.)
    For example:

    ---KeyID=A1B2C3D4
    ---KeyPass=Your_Key_Passphrase_1
    
    ---KeyID=F6A1B2C3
    ---KeyPass=Your Key Passphrase 2 With Spaces Optional

    ---KeyPass=This passphrase has no KeyID associated with it


    If you have the nym command cryptrecv turned off on your account, and you
    receive no public-key encrypted mail, you do not need to enter any
    "---KeyPass" lines.

    
    Save the ini file.


Decrypting Your Mail
====================

    You must save your mail messages to a file. Some mail programs (such as
    Agent) allow you to save a group of messages into one file.  Simply select
    them and choose Save Messages As...

    Other mail programs require you to save one message at a time to separate
    files.

    Depending on which kind of software you use, choose one of the following
    methods:

    Method One
    ----------

    If your mail program can save multiple messages to a single file, save the
    messages to a file named "mail.txt" in the same directory as dec.exe.  


    Method Two
    -----------

    If your mail program requires you to save each message individually, save
    them as "mail.1", "mail.2", "mail.3", etc., into the directory containing
    dec.exe. [Note, some programs will add an extension unless you surround the
    filename with double quotes.]



    Once the mail is saved, run dec.exe.  If you used method one, it will first
    parse the file "mail.txt" and break it into separate files.

    Next it will attempt to decrypt your mail, saving the output to the file
    "dec.txt"

    When the program finishes, load the file "dec.txt" into your editor.

    The original mail files will be deleted automatically.


    Importing
    ---------
    
    Alternatively, Decrypt can import messages directly from Agent, Netscape,
    and Eudora.  See the end of this document.


Notes
=====

    If you use Method One to save one multi-message file, any messages which are
    not PGP messages will be ignored and will not appear in the output file.

    Unlike previous versions of Decrypt, version 2 works equally well regardless
    of whether your reply-blocks use the same number of conventional
    decryptions, or whether you have one secret-key passphrase or several.  (If
    you have multiple secret-key passphrases, it is advisable to set the KeyID
    for each key in dec.ini.)

    Note that you can use much larger and more secure conventional passphrases
    for your accounts since you aren't typing them manually.  For example:
    YDg2LPJnQVtWt4LUrEo+qVUl2 (If using ultimately *random text* for a
    passphrase, 22 characters is sufficient, beyond which no security is
    gained.)  Both Potato and Jack B. Nymble can generate random passphrases in
    Nym Books.

    If Decrypt is unsuccessful at decrypting or decoding any part of a message,
    it will write the PGP message verbatim to the output file.


Securing the INI File
=====================

    Decrypt can secure your ini file so that your passphrases are not
    vulnerable. It encrypts the file with a passphrase you specify.  Each time
    you run the program, you will be prompted for this passphrase once, and all
    your mail will be decrypted.  This passphrase does not need to be the same
    as your account phrases.

    To secure your INI file, enter DOS and type:
    dec +secure

    (or use the shortcut)
    You will be prompted for a passphrase to use.  The ini file will be
    encrypted as dec.pgp.

    If you need to desecure your ini file (to edit it), enter:
    dec -secure

    and the procedure will be reversed.

    If you ever forget the passphrase, there is a clean copy of the ini file
    (without your passphrases) in dec.bak.
    copy dec.bak dec.ini



Advanced Features
=================

    You do not need to know the information in this section to use the program.
    However it is recommended that you read it at some point to familiarize
    yourself with other options and levels of security available.

File Wiping
-----------
    You can turn on file wiping in the ini file by setting
    ---DelWith=pgp +v=0 -w
    or
    ---DelWith=zapfile
    or
    ---DelWith=zapfile /2  (for two pass wiping)

    or any program you prefer.  Note that zapfile is a DOS program which seems
    to work well in Windows.  It may have unpredictable results in other
    operating systems.  Use at your own risk.

    Note that Decrypt uses many temporary files.  Setting DelWith to a slow file
    wiping utility, such as PGP, will significantly reduce performance.
    

Output and Input Files
----------------------
    Normally, if the output file already exists, new output is appended to it.
    To overwrite the existing file, set the following ini option:
    ---OverWrite=yes

    If you have DelWith set for wiping, the file will be wiped before it is
    overwritten.


    To change the default output file, you may set it in the ini file.   For
    example:
    ---OutputFile=d:\temp\mymail.txt

    To set the default input file(s), for example:
    ---InputFile=d:\stuff\msg

    In this example, Decrypt would first look for the file "msg.1", and if that
    wasn't found would look for "msg".  If you do provide an extension, all your
    messages must be saved to one file.


Workpath
--------
    You can set the directory where you want temporary files to be written, for
    example a RAMdrive.  Use the form:
    ---WorkPath=e:\temp

    The default workpath is the inipath (directory containing dec.ini.)


RAMdrives
---------
    If you have a RAMdrive configured on your system, you may wish to arrange it
    so that you can type your passphrase once per session, and dec.ini will
    remain on the ramdrive unencrypted until you power down.

    Normally, Decrypt will wipe a secured INI file after reading it.  You can
    turn wiping off with:
    ---WipeINI=no

    Note that setting this on a physical drive will defeat the purpose of
    +secure.


Prompting
---------
    If Decrypt encounters a message which the set passphrases will not decrypt,
    it can prompt you for the passphrase.  To turn on this feature:
    ---PromptConv=yes
    to be prompted for conventional passphrases, and:
    ---PromptKey=yes
    to be prompted for secret-key passphrases.


Prior Blocks
------------
    If a block of passphrases is designated as a prior block, such as:
    
    ---prior
    passphrase
    passphrase
    passphrase
    ---endblock
    
    It will have lowest priority when Decrypt is attempting to find the
    passphrase.  Passphrases in a prior block will be used after the other
    blocks have been tried.
    

Command Line
============

    Decrypt's usage is as follows:

    To decrypt mail:
    dec [-z"passphrase"] [-diag] [-m] [-p inipath] [-o outputfile]
            [-w workpath] [inputfile]

    To secure/desecure dec.ini:
    dec [-p inipath] +secure|-secure

    The "-diag" switch enables diagnostic mode.  This can also be enabled in
    dec.ini, or by pressing Esc while Decrypt is running.

    The -m switch causes Decrypt to prompt for a keypress when it has finished.

    inipath is the directory containing dec.ini.

    Command line parameters override ini file settings.


Attachments
===========
    
    Decrypt will attempt to decode PGP, UUEncoded, and MIME attachments.  If
    successful, binary files be saved to the Attachment Directory specified in
    dec.ini.  A message will be added to the output file indicating that the
    attachment was saved.
    
    UUE and MIME decoding may be turned off by specifying:
    ---UUE=no
    ---MIME=no
    
    Saving of all binary attachments, including PGP encrypted binary files, may
    be turned off with:
    ---SaveBinary=no
    

Multi-Part FixedSize Messages
=============================

    If you have the fixedsize option turned on for your nym account, the
    oversize multi-part messages can be reassembled and decrypted automatically
    by specifying
    ---FixedSize=yes
    
    Because all the pieces are required for assembly, and because a given
    Decrypt session may not contain all the required messages, Decrypt saves
    the fixedsize messages to a default path specified by:
    ---FixedSizePath=
    
    Once all the pieces are present, they are assembled and deleted, and the
    resulting message is decrypted.  Enabling fixedsize also causes GARBAGE
    sections to be removed.

    Decrypt will include a message in the output file, indicating that a
    fixedsize part has been saved.  If you do not require this for each
    individual part, set
    ---FixedSizeInfo=no
    
    In this case, Decrypt will write a message to the screen only.

    NOTE: You must have +cryptrecv set on your nym account for Decrypt's
    fixedsize feature to operate correctly.  If you do not, set
    ---FixedSize=no


Importing and Exporting Messages - Agent, Netscape, Eudora
==========================================================

    Decrypt can write its output file in UNIX Message File Format.  These
    messages may then be read by Agent, Netscape, Eudora, and any software which
    supports this format.
    
    To enable this feature, change the following line in dec.ini to:
    ---unixout=yes
    

    See the section below for the email software you use.
    
        
Forte's Agent and Free Agent
----------------------------

    Set Decrypt's InputFile to any file you wish to use:
        
    ---InputFile=c:\dec\mail
    
    For OutputFile, specify any convenient file:
    
    ---OutputFile=c:\dec\dec.txt
    
    ---UnixOut=yes

    It is also generally best to set:
    
    ---OverWrite=yes
    
    To decrypt messages, select them in Agent, then select Save Messages As from
    the File menu (File|Save Messages As).  Enter the name of your input file,
    in this example "c:\dec\mail"
    
    Run Decrypt.  After Decrypt has run, in Agent select File|Import Messages.
    Enter the output filename, in this example "c:\dec\dec.txt".  Agent will
    import the decrypted messages, filtering them into folders according to your
    email filters.
    
    If you turn off Decrypt's MIME and UUE functions in DEC.INI, you can save
    attachments in Agent instead.
    

Netscape 3.0 and 4.0
--------------------

    When using Netscape Mail, you have two options for sending your mail to
    Decrypt.  You can save individual messages to separate files, such as
    mail.1, mail.2, etc.  Or, you can send a whole mail folder to Decrypt.  To
    do this:
    
    In DEC.INI, set InputFile to your Netscape Inbox, or other mail folder.
    (Note, Netscape's mail folders are really files.)  For example:
    
    ---InputFile=c:\progra~1\Netscape\Mail\Inbox
    
    Also, be sure to set:
    
    ---KeepMail=yes
    
    so that Decrypt does not delete the Netscape mail folder.
    
    
    If you want Decrypt to export the Decrypted messages directly to a Netscape
    Folder, set OutputFile to the name of the folder.  (If it doesn't exist, it
    will be created.)  For example:
    
    ---OutputFile=c:\progra~1\Netscape\Mail\DecMail
    
    ---UnixOut=yes
    
    To have Decrypt add messages to the folder, set:
    
    ---OverWrite=no
    
    Or, set it to yes to cause Decrypt to replace the folder each time.
    
    [Note, depending on where Netscape is located on your system, Decrypt may
    report an error that the pathname is too long.  If this happens, Netscape
    4.0 allows you to change the location of your Mail directory using
    Edit|Preferences|Mail and Groups|Mail Server|More Options.]
    

    Before Decrypting your mail folder, be sure to select File|Compress Folder
    (or File|Empty Trash Folder).  Otherwise, previous messages which you
    thought were deleted will be sent to Decrypt, and decrypted messages may
    not appear.
    
    Finally, run Decrypt.  After it runs, open the new folder in Netscape to
    read your mail.
    
    If you turn off Decrypt's MIME and UUE functions in DEC.INI, you can save
    attachments in Netscape instead.

    Some versions of Netscape may complain (at times) that the mail folder has
    been altered by another program.  If you get this error, simply delete the
    index file associated with the folder, "filename.snm".  In this example,
    DecMail.snm should be deleted.  This will cause Netscape to rebuild the
    index file.  No mail will be lost.


Eudora Pro and Light (version 3.0.x)
------------------------------------
    (Thanks to Medicine Man for contributing these instructions.)


    Decrypt can read directly from and write directly to Eudora's mailboxes.
    Once you have everything configured properly, decrypting and reading your
    mail is relatively easy.

    Getting Eudora Ready

    While it really is not absolutely essential that any changes be made to
    Eudora, it makes things easier if you set up two new mailboxes.  One for
    encrypted mail which will serve as the input file for Decrypt and the other
    for decrypted mail.  You may also want to set up a filter so that all of
    your incoming encrypted mail gets placed automatically in that mailbox.
    Filtering on the keyword "anonymous" from any header seems to work well.


    Setting up Decrypt

    Modify the Dec.ini file as follows:

    ---InputFile=c:\eudora\(your encrypted mailbox name in DOS format).mbx

    ---KeepMail=yes

    ---OutputFile=c:\eudora\(your decrypted mailbox name in DOS format).mbx

    ---UnixOut=yes

    ---OverWrite=no


    Running Decrypt

    1) Prior to running Decrypt, make sure that only the messages that you want
    to decrypt are contained in your encrypted mailbox.  Remove all others by
    transferring or deleting them.  After removing any messages, you MUST
    compact the mailbox in order to really delete them from it.  To compact the
    mailbox, you could use Special/Compact Mailboxes from the menu.  However,
    this will compact all of your mailboxes.  Depending on how many you have,
    this could take some time.  A better way is to open your encrypted mailbox
    so that the message summary window is displayed.  There is a button in the
    lower left hand corner of the screen next to the horizontal scroll bar.
    This button contains three sets of numbers separated by slashes (the first
    number represents the number of messages that the mailbox contains, the
    second is the disk space in KB that the messages are occupying, the third is
    the amount of disk space that would be regained if the mailbox were to be
    compacted).  If the numbers are grayed out and the third number reads zero,
    then the mailbox does not have to be compacted.  If the numbers are not
    grayed out, then click on the button and this mailbox will be compacted.

    2) Make sure that the mailbox is closed.

    3) Run Dec.exe

    4) Open the decrypted mailbox.  The following message will pop up:  "Mailbox
    Decrypted has been changed since its Table of Contents was created.  Do you
    wish to use the old Table of Contents or create a new one?"  Click the
    "Create New" button.  The message summary window will open and you will then
    be able to select and read your decrypted mail.  If you transfer or delete
    any messages from this mailbox, remember to compact it afterward.



--------------------------------------------------------------------------------
For version updates visit
http://www.geocities.com/SiliconValley/Bay/4362

Decrypt-8086 is available for 8086 processors (IBM XT).

A German tanslation of this document is available at
http://www.fen.baynet.de/~na1321/security/potato.htm

