# Is Open PGP, FIPS 140-2 compliant?

We are looking for a secure printing solution and I need to verify that Open PGP is FIPS 140-2 compliant?

Any chance either of you would have a diagram of the flow for this?

My boss asked.

Maybe help to clarify what is the "flow" that you meant?You mean PGP workflow?

- First, PGP generates a random session key using one of two (main) algorithms. This key is a huge number that cannot be guessed, and is only used once.
- Next, this session key is encrypted. This is done using the public key of the intended recipient of the message. The public key is tied to a particular person’s identity, and anyone can use it to send them a message.
- The sender sends their encrypted PGP session key to the recipient, and they are able to decrypt it using their private key. Using this session key, the recipient is now able to decrypt the actual message.

That might be what he wants. Thank you I'll send it to him and let you know

Thanks

