Expiration dashboard
Keys and operations — Expiration dashboard
Where: Tools → Expiration dashboard.
This list is for lifecycle: what is expiring, expired, or revoked — including rows with no username. Those rows still show Key ID (hex) so you can find them on the grid.
What you see
- Keys with an end date (soon or already past)
- Revoked keys (red on the main grid)
- Keys that never expire, if that group is shown so you can see they have no date
Expired on the grid is purple. Revoked is red. The dashboard is not only “dates in the next month.”
What to do
- Open the dashboard.
- Identify the key by name or Key ID hex.
- On the key store, select that key.
- If you still use it and you have the secret key, extend expiration (Keys menu) and enter the key passphrase.
- If it should die, stop encrypting to it; revoke it if it is yours.
- Update recipient groups so jobs and Watch folder do not point at a dead key.
If it fails
- Cannot extend — no secret key, or passphrase wrong.
- Evaluation copy — new/extended dates may still be capped at 30 days from now.
- You only looked at names — use Key ID hex when the user ID is empty.
Next
Revoke, trash, and restore. Policy notes for 1024 and evaluation caps.