Using the program — Trust, fingerprint, and QR

Where: select a key → Properties, QR, right-click Verified, or Keys menu.

Import only means “this key is in the vault.” Verified means you compared the fingerprint with the owner.

Fingerprint

  1. Select the key.
  2. Open Properties.
  3. Read the full fingerprint (long hex), user IDs, created, valid until, algorithm, size, public vs secret, capabilities, revoked/expired.

Compare that fingerprint with what the owner shows you (in person, known-good channel, or their ceremony sheet). Do not trust a fingerprint that arrived in the same email as the key file alone.

Mark Verified

  1. After the fingerprints match, right-click the row → set Verified (or use the trust command on the form).
  2. The grid trust column should show verified, not only “imported.”

Clear or leave unverified if you have not checked. Group filters do not change trust.

QR

  1. Keys → QR (or the QR command on the selected key).
  2. The code contains the full public key, not only a short ID.
  3. The other person scans or compares; they still should read the fingerprint in Properties.

QR is for public material. Do not put a secret key in a QR you will display.

Ceremony sheet

Key ceremony sheet prints user ID, key ID, fingerprint, algorithm, and dates with two operator sign-off lines. Use it when two people confirm a fingerprint. Print one key or print a group.

If it fails

  • QR too dense on a small screen — use Properties fingerprint instead.
  • Two keys with similar names — match Key ID hex and fingerprint, not the display name only.
  • “Unverified” cut off on the grid — widen the column; the value is still stored.

Next

Encrypt only to keys you have verified when the data matters. Unverified public keys are fine for a first connectivity test, not for secrets.