Trust, fingerprint, and QR
Using the program — Trust, fingerprint, and QR
Where: select a key → Properties, QR, right-click Verified, or Keys menu.
Import only means “this key is in the vault.” Verified means you compared the fingerprint with the owner.
Fingerprint
- Select the key.
- Open Properties.
- Read the full fingerprint (long hex), user IDs, created, valid until, algorithm, size, public vs secret, capabilities, revoked/expired.
Compare that fingerprint with what the owner shows you (in person, known-good channel, or their ceremony sheet). Do not trust a fingerprint that arrived in the same email as the key file alone.
Mark Verified
- After the fingerprints match, right-click the row → set Verified (or use the trust command on the form).
- The grid trust column should show verified, not only “imported.”
Clear or leave unverified if you have not checked. Group filters do not change trust.
QR
- Keys → QR (or the QR command on the selected key).
- The code contains the full public key, not only a short ID.
- The other person scans or compares; they still should read the fingerprint in Properties.
QR is for public material. Do not put a secret key in a QR you will display.
Ceremony sheet
Key ceremony sheet prints user ID, key ID, fingerprint, algorithm, and dates with two operator sign-off lines. Use it when two people confirm a fingerprint. Print one key or print a group.
If it fails
- QR too dense on a small screen — use Properties fingerprint instead.
- Two keys with similar names — match Key ID hex and fingerprint, not the display name only.
- “Unverified” cut off on the grid — widen the column; the value is still stored.
Next
Encrypt only to keys you have verified when the data matters. Unverified public keys are fine for a first connectivity test, not for secrets.