Getting started — Add a key

The key store is empty until you add at least one key. You can compose a new pair or import a key you already have.

Compose a new key

  1. Open Keys → Compose key (or the equivalent Compose command).
  2. Enter a name. Email is optional but recommended.
  3. Choose algorithm (for a first key, Ed25519+X25519 or RSA 3072).
  4. Set hash, cipher, and compression if you do not want the defaults (SHA512, AES256, ZIP are the usual defaults).
  5. Set Valid until, or Never expire if the license allows it.
    Evaluation copies cannot use Never expire; new keys must expire within 30 days.
  6. Enter a key passphrase, confirm it (minimum eight characters). Optional: generate a password and use Show password.
  7. Optional: Mark as verified if this is your own key.
  8. Choose Create. Large RSA (4096) can take a while; stay on the window.
  9. The new row appears in the key store.

1024-bit RSA is blocked for new keys.

Import a key you already have

Use this for a public key someone sent you, or a secret key you exported from another program.

  • File: Keys → Import, and choose .asc, .pgp, or .gpg.
  • Armored block: paste a BEGIN PGP PUBLIC KEY BLOCK or PRIVATE KEY BLOCK into Import key block / clipboard import.
  • Several files: Bulk import (CSV template, folder, or ZIP). Use dry-run first if you want to see duplicates, expiry, and revocation before anything is saved.

If the key is already in the store, expired, revoked, or too weak (for example 1024-bit for encrypt), you get a message and the key may be skipped.

After the key is in the grid

  1. Select the row.
  2. Open Properties and check fingerprint, user ID, created, valid until, public vs secret.
  3. For a key you will encrypt to in person, compare the fingerprint (or QR) with the owner. Then set trust to Verified.

Imported public keys are not automatically “verified.”

Public vs secret

  • Public only — you can encrypt to it and verify signatures. You cannot decrypt or sign.
  • Public + secret — you can decrypt and sign, after you enter that key’s passphrase.

Next

Encrypt a test file to your own key and decrypt it before you use the key for real data. See Getting started → Encrypt a test file.