BACK TO HOME

NEXTGEN Widget Encrypt3 — when OpenPGP security matters.

by NextGen Widget Software


Using the program

Sign in first. These topics are the work you do with keys and with files or text. The vault password and a key passphrase are not the same thing — start there.

  1. Two passwords
    The login password opens the vault. It is created on the login screen and is never stored as an OpenPGP secret.
    Each secret key has its own passphrase, set when you compose or import that key. Decrypt, sign, revoke, and change-key-password all ask for the key passphrase.
    The program cannot recover either password. A backup of the vault does not help if you have forgotten the login password that wraps it.
  2. Create your first key
    Keys → Compose key. Name is required; email is optional. Ed25519+X25519 is a sound default. Set the key passphrase and confirm it.
    On a full license you may choose Never expire. On an evaluation license, Never expire is unavailable and Valid until cannot be more than 30 days from today.
    If you created the key on this PC, you may mark it verified before you leave the form.
  3. Import a key
    Keys → Import. Yes opens a file (.asc, .pgp, or .gpg). No, or Import pasted key block, takes a full BEGIN PGP PUBLIC KEY BLOCK and/or BEGIN PGP PRIVATE KEY BLOCK. Both blocks in one paste become one key pair.
    The program tells you if the key is already in the store, revoked, expired, or under 2048 bits. Weak keys are not imported. Check the fingerprint before you mark the key verified.
  4. Bulk import and the CSV template
    Keys → Bulk import / dry-run. You can add files, drop a folder, open a ZIP, or import a CSV. Run the dry-run and read the list before you write anything into the vault.
    Keys → Save CSV import template writes the matching CSV. The armored column is the key block itself. Group and notes are stored on the key and show up in the grid.
  5. File Task
    File → File tasks.
    • Encrypt file — pick the recipient. Output is a new file with a random name. The original stays where it is.
    • Decrypt file — the next tab. Uses the secret key’s passphrase and restores the original file name when the packet has it.
    • Sign and encrypt — recipient plus signer.
    • Decrypt and verify — says whether the signature is valid and which key signed.
      An armor comment is optional. “Also encrypt to me” adds a second recipient you choose, on that same file, not a second file.
  6. Text Task
    Text → Text tasks. Tabs: Encrypt text, Decrypt text, Sign and encrypt, Decrypt / verify, Clear-text sign, Clear-text verify.
    A blank box is not encrypted. Result boxes are yellow. Clear-text verify needs the whole block from BEGIN PGP SIGNED MESSAGE through END PGP SIGNATURE.
  7. Revoke, trash, and restore
    Keys → Revoke key needs the key passphrase and turns the row red immediately. A revoked or expired key cannot encrypt or sign. A secret key may still decrypt older files.
    Create, export, or apply a revocation certificate when you need a certificate file instead of an immediate revoke.
    Send to trash only hides the row. Open trash bucket to restore it. Trash is not revocation.
  8. Trust, fingerprint, and QR
    “Verified” means you checked the fingerprint. It is not set automatically on import.
    Keys → Properties (or double-click) shows the full fingerprint. Keys → QR code shows the full public key so another person can compare it. Keys → Toggle trusted, or the grid right-click, sets or clears verified after that check.