Revoke, trash, and restore
Using the program — Revoke, trash, and restore
Where: key store selection, then Keys → Revoke, Trash, or Trash window.
Revoke and trash are different. Revoke is a cryptographic “do not use this key.” Trash hides a row in the vault until you restore or delete it.
Revoke
Use revoke when your secret key must never sign or be used as a recipient again (lost passphrase policy, key replaced, compromise).
- Select the key (it must include secret material for a self-revocation).
- Keys → Revoke.
- Enter that key’s passphrase if asked.
- Confirm. The row turns red.
A revoked key must not be chosen as signer or encrypt recipient. Decrypt with the secret may still be possible so old files can be opened.
Revocation certificate
If you saved a revocation certificate when the key was created:
- Keep that certificate offline.
- When you need it, use the command to apply the revocation certificate to that key (Keys menu on the selected key).
- The store should then show the key as revoked (red).
Applying a certificate you did not create for that fingerprint will fail.
Trash
- Select a key you want off the live grid but not destroyed.
- Send it to Trash.
- Open the Trash window to see those keys.
- Restore puts the row back in the key store.
- Permanent delete from Trash cannot be undone from the grid.
Trash is not a revocation. A trashed key that was valid is still valid if restored.
Colors on the live grid
- Red — revoked
- Purple — expired
- Normal — in date and not revoked
Expired and revoked are not the same color and not the same action.
If it fails
- No secret key — you cannot self-revoke someone else’s public key.
- Revoked key still offered as signer in Text Task — do not use it; pick another signer.
- You revoked by mistake — you cannot “un-revoke.” Compose or import a new key and tell people the new fingerprint.
Next
Export a fresh public key for the replacement. Update recipient groups so they do not point at the revoked row.