Policy notes
Product — Policy notes
Encrypt3 blocks some OpenPGP choices on purpose. The message should say the key is obsolete and vulnerable, not only “policy.”
Key size
- 1024-bit (and other blocked weak sizes) cannot be composed.
- They cannot be used to encrypt.
- Import may refuse them or warn; do not use them as recipients.
Use RSA 3072/4096 or Ed25519+X25519 for new work.
Evaluation
- Newly composed keys must expire within 30 days.
- Never expire is disabled.
- If you pick a later date, it is snapped back and you are told.
- A full license sets that cap to off.
Expired keys (purple)
- Cannot be used to encrypt.
- Decrypt with a secret key may still work so you can open old files.
- Extend expiry only if you have the secret key and the license allows the new date.
Revoked keys (red)
- Cannot sign.
- Cannot be chosen as an encrypt recipient.
- May still decrypt old ciphertext if the secret material is in the vault.
Signing
The signer must be a secret key that is not revoked. Text Task and File Task should refuse a revoked signer.
Watch folder and groups
Watch folder encrypts only to the key you selected. If that key later expires or is revoked, files go to Failed until you pick a valid key and Save.
Next
Expiration dashboard. Create your first key. Licensing for the 30-day evaluation cap.