Create your first key
Using the program — Create your first key
Where: Keys → Compose key.
This builds a new OpenPGP key and stores it in the vault. It is not the vault login.
Before you start
- You are signed in.
- Evaluation copy: the key must expire within 30 days. Never expire is off.
- Licensed copy: Never expire is allowed.
- RSA 1024 is blocked.
Steps
- Open Compose key.
- Name — required (this becomes the user ID).
- Email — optional; use it if you will look the key up by address.
- Algorithm — for a first key use Ed25519+X25519 or RSA 3072.
Also available: RSA other allowed sizes, DSA+ElGamal, ECDSA+ECDH (including NIST / Brainpool curves the form lists). - Key size — only where the algorithm needs it (RSA). Prefer 3072 or 4096, not 1024.
- Hash, cipher, compression — defaults are appropriate (typically SHA512, AES-256, ZIP). Change them only if you must match someone else.
- Valid until — pick a date, or Never expire if the license allows it.
- Passphrase — at least eight characters, then confirm.
Optional: Generate password, set length, use the strength meter.
Optional: Show password / Show generated password. - Optional: Mark as verified if this is your own key and you accept the fingerprint you are about to create.
- Choose Create. Large RSA can take a long time; leave the window open.
- Close Compose. The key store shows a new row (public and secret).
After Create
- Select the row → Properties. Check name, email, Key ID hex, fingerprint, algorithm, size, created, valid until, public/secret.
- Optional: QR (full public key) or ceremony sheet if someone else must confirm the fingerprint.
- Run Encrypt a test file to this key and decrypt it on the same PC.
If Create fails
- Name empty.
- Passwords do not match or shorter than eight characters.
- Evaluation: date beyond 30 days or Never expire still selected.
- 1024 or another blocked size.
- You walked away and idle lock closed the window — sign in and compose again (unfinished compose is discarded).
Next
Export the public key if others will encrypt to you. Keep the secret key in the vault; export secret only to a safe backup you control.