Getting started — Encrypt a test file

Do this once after you add a key. Use a throwaway text file, not important data.

What you need

  • A key in the store that can encrypt (not expired, not revoked; not a blocked 1024-bit key)
  • If you will decrypt on this PC, that key must include the secret part
  • A small test file, for example test.txt on the Desktop

Encrypt

  1. Open File Task.
  2. Open the Encrypt file tab.
  3. Choose the input file.
  4. Choose the recipient (the key you are encrypting to). For this test, choose your own key.
  5. Optional: check ASCII armor if you want a text .asc-style file.
  6. Optional: enter an armor comment only if armor is on and you want a Comment header.
  7. Optional: Also encrypt to me (recovery copy) adds a second recipient you select. Leave it off for the first test so only one key can decrypt.
  8. Choose Encrypt.
  9. Pick where to save the output. Encrypted names use a generated name (not the original filename).

The Version header on armored output uses this product name.

Decrypt

  1. Stay on File Task and open the Decrypt file tab (next to Encrypt file).
  2. Choose the encrypted file you just created.
  3. When asked, enter the key passphrase for the secret key that can open it (not the vault login, unless you used the same password).
  4. Save the output. Decrypt restores the original file name and extension.
  5. Open the result and confirm it matches test.txt.

If it fails

  • Policy / weak key — that key cannot be used to encrypt. Use a stronger key.
  • Expired / revoked — choose another recipient.
  • Wrong passphrase — the secret key password is incorrect.
  • Cannot decrypt — the file was not encrypted to a secret key in this vault (recovery copy off and recipient was someone else).

Next

Use File Task for real files the same way. For many files in a folder, see Folder Task. For messages, see Text Task