Using the program — Two passwords

Encrypt3 never uses a single password for everything. Mixing them up is the usual reason decrypt or sign-in fails.

Vault login

  • Created with Create account.
  • Changed with Change login password.
  • Unlocks the .ngw3 vault: every key row, settings, groups, audit.
  • Used on the sign-in window and the idle lock screen.
  • Minimum eight characters; confirm when you set it.
  • Three wrong entries at sign-in and the program exits.

If you forget this password, the vault file cannot be opened. A backup of the .ngw3 without the login is not usable.

Key passphrase

  • Set when you Compose a key or when you Change key password.
  • Unlocks one secret key: decrypt and sign.
  • Asked for in File Task, Folder Task, Text Task, clipboard decrypt, and some key operations (extend expiry, revoke, export secret).
  • Each secret key can have a different passphrase.
  • Public-only keys have no passphrase prompt for decrypt/sign because they cannot do those jobs.

Same characters, two locks

You may type the same string for both. The program still stores them separately. Changing the login does not change key passphrases. Changing a key passphrase does not change the login.

What to type where

Window

Password to use

Sign-in / lock

Vault login

Create account

New vault login

Change login password

Old vault login, then new vault login

Compose key

New key passphrase

Change key password

Old key passphrase, then new key passphrase

Decrypt / sign / sign-and-encrypt / clear-sign

That key’s passphrase

Typical mistakes

  • Decrypt dialog: typed the vault login.
  • Sign-in: typed a key passphrase.
  • Imported a public key and expected a passphrase prompt to decrypt.
  • Two secret keys: used key A’s password on a file encrypted to key B.

After a good first test

Write down (offline) that there are two secrets, and which one opens the vault. Do not store either in the audit log or in a screenshot of the welcome bar.