Using the program — Revoke, trash, and restore

Where: key store selection, then Keys → Revoke, Trash, or Trash window.

Revoke and trash are different. Revoke is a cryptographic “do not use this key.” Trash hides a row in the vault until you restore or delete it.

Revoke

Use revoke when your secret key must never sign or be used as a recipient again (lost passphrase policy, key replaced, compromise).

  1. Select the key (it must include secret material for a self-revocation).
  2. Keys → Revoke.
  3. Enter that key’s passphrase if asked.
  4. Confirm. The row turns red.

A revoked key must not be chosen as signer or encrypt recipient. Decrypt with the secret may still be possible so old files can be opened.

Revocation certificate

If you saved a revocation certificate when the key was created:

  1. Keep that certificate offline.
  2. When you need it, use the command to apply the revocation certificate to that key (Keys menu on the selected key).
  3. The store should then show the key as revoked (red).

Applying a certificate you did not create for that fingerprint will fail.

Trash

  1. Select a key you want off the live grid but not destroyed.
  2. Send it to Trash.
  3. Open the Trash window to see those keys.
  4. Restore puts the row back in the key store.
  5. Permanent delete from Trash cannot be undone from the grid.

Trash is not a revocation. A trashed key that was valid is still valid if restored.

Colors on the live grid

  • Red — revoked
  • Purple — expired
  • Normal — in date and not revoked

Expired and revoked are not the same color and not the same action.

If it fails

  • No secret key — you cannot self-revoke someone else’s public key.
  • Revoked key still offered as signer in Text Task — do not use it; pick another signer.
  • You revoked by mistake — you cannot “un-revoke.” Compose or import a new key and tell people the new fingerprint.

Next

Export a fresh public key for the replacement. Update recipient groups so they do not point at the revoked row.