Resources¶
- gnupg.org, keys.openpgp.org (keyserver), GPG, PGP and OpenPGP explained, GPG for humans
- Creating GPG keypairs (Red Hat)
Create a key¶
gpg --full-generate-key
Prompts, in order: key type (the default RSA and RSA is fine, or choose ECC "Curve 25519" on GnuPG 2.1+), key size (4096 for RSA), expiry, then your real name and email address.
Give the key an expiry (for example 2y) instead of "does not expire". You can extend it later, and an expiry limits the damage if you lose the key. Protect the secret key with a strong passphrase, and create a revocation certificate now, before you need it:
gpg --output revoke-key.asc --gen-revoke [email protected]
Store that file somewhere safe and offline.
List, export, import, delete¶
gpg --list-keys # public keys
gpg --list-secret-keys --keyid-format=long
gpg --armor --export [email protected] > public.asc
gpg --armor --export-secret-keys [email protected] > secret.asc # protect this file!
gpg --import public.asc
gpg --delete-secret-keys <KEYID> # secret part first ...
gpg --delete-keys <KEYID> # ... then the public part
Use the full fingerprint or the long key ID of the key you mean. Example key listing:
pub rsa4096 2026-01-15 [SC]
0123456789ABCDEF0123456789ABCDEF01234567
uid [ultimate] Your Name <you@example.com>
sub rsa4096 2026-01-15 [E]
Sign, verify, encrypt, decrypt¶
echo "My GPG file" > gpg.txt
gpg --sign gpg.txt # creates gpg.txt.gpg (signed, compressed; not encrypted)
gpg --verify gpg.txt.gpg
# gpg: Good signature from "Your Name <[email protected]>" [ultimate]
gpg --output decrypted.txt --decrypt gpg.txt.gpg
diff decrypted.txt gpg.txt
gpg --clearsign gpg.txt # readable text + signature (gpg.txt.asc)
gpg --detach-sign gpg.txt # separate signature file (gpg.txt.sig)
gpg --encrypt --recipient [email protected] file.txt # encrypt for someone else
gpg --symmetric file.txt # passphrase-only encryption
Entering the passphrase on the command line (scripts and headless use)¶
Normally gpg-agent asks for the passphrase through a GUI or terminal pinentry. To supply it non-interactively:
# ~/.gnupg/gpg-agent.conf
allow-loopback-pinentry
gpgconf --kill gpg-agent # restart the agent to pick up the setting
gpg --batch --pinentry-mode loopback --passphrase-file ~/.gnupg/pass.txt \
--output out.txt --decrypt file.gpg
Keeping a passphrase in a file defeats much of its purpose. chmod 600 it, and prefer a secrets manager or a dedicated, low-privilege signing key for automation. Do not use --passphrase "secret" on the command line, where it is visible in ps and history.
Cache lifetime for the agent (see also pass):
echo "default-cache-ttl 600" >> ~/.gnupg/gpg-agent.conf
gpg-connect-agent reloadagent /bye # apply / clear the cache
Manage installed RPM package-signing keys¶
RPM systems import vendor GPG keys as pseudo-packages named gpg-pubkey. Reference: How to remove RPM package GPG keys.
sudo rpm -qa gpg-pubkey
sudo rpm -q gpg-pubkey --qf '%{NAME}-%{VERSION}-%{RELEASE}\t%{SUMMARY}\n'
sudo rpm --erase --allmatches gpg-pubkey-<version>-<release>
Only remove a key if you are sure no repository you still use is signed with it.