基于OWA与JavaScript实现邮件端到端加密的私钥存储可行性咨询
Is your proposed approach feasible?
The short answer is yes, it's technically possible, but there are critical challenges you'll need to address to make it secure and functional:
- OWA's JavaScript Environment Constraints: OWA enforces strict Content Security Policies (CSP) that might restrict certain crypto operations or third-party libraries. You'll need to ensure your code complies with OWA's CSP rules, especially if using external encryption libraries like OpenPGP.js. Additionally, OWA's sandboxed environment may limit access to persistent storage options or browser-level crypto APIs in some scenarios.
- Private Key Security Risks: Storing private keys in OWA's client-side storage (like
localStorage,sessionStorage, or evenIndexedDB) exposes them to browser-based threats—if the user's browser is compromised (e.g., via malware, phishing, or shared devices), the private key could be exfiltrated. While these storage options are device-local, they aren't hardware-secured (unlike TPMs or secure enclaves). Also, some OWA configurations may clear session storage when the user logs out, risking key loss unless you implement persistent, encrypted storage. - Performance & Compatibility: JavaScript-based asymmetric encryption (e.g., RSA, ECC) can be slow for large email attachments, especially on lower-end devices. You'll also need to test across browsers (Chrome, Edge, Firefox) since Web Crypto API support can vary, and OWA's behavior differs slightly across platforms.
- User Experience: Integrating encryption seamlessly into OWA's compose/flow requires careful DOM manipulation, which can break when OWA updates its UI—you'll need to handle versioning and UI changes to avoid broken functionality.
Cross-Platform Alternatives for OWA (No COM Add-ins)
Since COM add-ins are out of the question for cross-platform support, here are the most viable options:
1. Microsoft 365 Office Add-ins (Web-Based)
This is the official, cross-platform way to extend OWA (works with web OWA, Outlook desktop, Mac, and mobile). You can build a web add-in using HTML/CSS/JS that integrates directly with OWA's compose/read interfaces via the Office JS API.
- Encryption Implementation: Use the browser's native
Web Crypto APIor libraries like OpenPGP.js to handle end-to-end encryption. For private key storage, useIndexedDB(with the key encrypted by a user-provided passphrase) or leverage the Web Crypto API's non-extractable keys (extractable: false) to keep the private key in the browser's secure crypto store, preventing it from being accessed directly by your code. - Advantages: Fully cross-platform, supported by Microsoft, and integrates natively with OWA's UI (e.g., add a "Encrypt" button to the compose toolbar).
- Considerations: You'll need to publish the add-in to the Microsoft App Source or deploy it internally via your organization's admin center.
2. Client-Side Encryption with OWA REST API
If you need more control, you can build a standalone web app (or browser extension) that interacts with OWA's REST API to fetch/send emails, handling encryption/decryption client-side.
- Workflow: The app would fetch unencrypted emails from OWA via the REST API, decrypt them locally using the user's private key, and let users compose encrypted messages that are sent back to OWA as encrypted blobs.
- Private Key Storage: Use browser-specific secure storage options like Chrome's
chrome.storage.local(with encryption) or Firefox'sbrowser.storage.local, or leverage Web Crypto's secure key storage. - Advantages: More flexibility than Office Add-ins, no dependency on OWA's UI sandbox.
- Considerations: Requires handling OAuth2 authentication for the OWA REST API, and you'll need to ensure the app complies with Microsoft's API rate limits and security policies.
3. Leverage OpenPGP with OWA Integration
Integrate an OpenPGP-compliant JS library (like OpenPGP.js) into either an Office Add-in or a browser extension. OpenPGP is a widely adopted standard, which means encrypted emails can be read by other PGP-compatible clients (e.g., Thunderbird, GPG).
- Key Management: Let users import/export PGP keys, and store the private key encrypted with a passphrase in browser storage. You can also integrate with hardware security keys (e.g., YubiKey) via the WebAuthn API for additional security, letting users store their private keys on a physical device instead of the browser.
Final Recommendations
If you proceed with your original approach, prioritize:
- Using non-extractable keys via the Web Crypto API to minimize exposure
- Encrypting the private key with a user passphrase before storing it
- Testing rigorously across all target browsers and OWA versions
For long-term maintainability and cross-platform support, Microsoft 365 Office Add-ins are the most robust option since they're designed specifically for extending OWA and Outlook across platforms.
内容的提问来源于stack exchange,提问作者Kostadinov

