Two passwords
Using the program — Two passwords
Encrypt3 never uses a single password for everything. Mixing them up is the usual reason decrypt or sign-in fails.
Vault login
- Created with Create account.
- Changed with Change login password.
- Unlocks the .ngw3 vault: every key row, settings, groups, audit.
- Used on the sign-in window and the idle lock screen.
- Minimum eight characters; confirm when you set it.
- Three wrong entries at sign-in and the program exits.
If you forget this password, the vault file cannot be opened. A backup of the .ngw3 without the login is not usable.
Key passphrase
- Set when you Compose a key or when you Change key password.
- Unlocks one secret key: decrypt and sign.
- Asked for in File Task, Folder Task, Text Task, clipboard decrypt, and some key operations (extend expiry, revoke, export secret).
- Each secret key can have a different passphrase.
- Public-only keys have no passphrase prompt for decrypt/sign because they cannot do those jobs.
Same characters, two locks
You may type the same string for both. The program still stores them separately. Changing the login does not change key passphrases. Changing a key passphrase does not change the login.
What to type where
|
Window |
Password to use |
|
Sign-in / lock |
Vault login |
|
Create account |
New vault login |
|
Change login password |
Old vault login, then new vault login |
|
Compose key |
New key passphrase |
|
Change key password |
Old key passphrase, then new key passphrase |
|
Decrypt / sign / sign-and-encrypt / clear-sign |
That key’s passphrase |
Typical mistakes
- Decrypt dialog: typed the vault login.
- Sign-in: typed a key passphrase.
- Imported a public key and expected a passphrase prompt to decrypt.
- Two secret keys: used key A’s password on a file encrypted to key B.
After a good first test
Write down (offline) that there are two secrets, and which one opens the vault. Do not store either in the audit log or in a screenshot of the welcome bar.