Andrew Mercer
on this page

Resources

Create a key

gpg --full-generate-key

Prompts, in order: key type (the default RSA and RSA is fine, or choose ECC "Curve 25519" on GnuPG 2.1+), key size (4096 for RSA), expiry, then your real name and email address.

Give the key an expiry (for example 2y) instead of "does not expire". You can extend it later, and an expiry limits the damage if you lose the key. Protect the secret key with a strong passphrase, and create a revocation certificate now, before you need it:

gpg --output revoke-key.asc --gen-revoke [email protected]

Store that file somewhere safe and offline.

List, export, import, delete

gpg --list-keys                        # public keys
gpg --list-secret-keys --keyid-format=long

gpg --armor --export [email protected] > public.asc
gpg --armor --export-secret-keys [email protected] > secret.asc     # protect this file!
gpg --import public.asc

gpg --delete-secret-keys <KEYID>       # secret part first ...
gpg --delete-keys <KEYID>              # ... then the public part

Use the full fingerprint or the long key ID of the key you mean. Example key listing:

pub   rsa4096 2026-01-15 [SC]
      0123456789ABCDEF0123456789ABCDEF01234567
uid           [ultimate] Your Name <you@example.com>
sub   rsa4096 2026-01-15 [E]

Sign, verify, encrypt, decrypt

echo "My GPG file" > gpg.txt

gpg --sign gpg.txt                     # creates gpg.txt.gpg (signed, compressed; not encrypted)
gpg --verify gpg.txt.gpg
# gpg: Good signature from "Your Name <[email protected]>" [ultimate]

gpg --output decrypted.txt --decrypt gpg.txt.gpg
diff decrypted.txt gpg.txt

gpg --clearsign gpg.txt                # readable text + signature (gpg.txt.asc)
gpg --detach-sign gpg.txt              # separate signature file (gpg.txt.sig)
gpg --encrypt --recipient [email protected] file.txt     # encrypt for someone else
gpg --symmetric file.txt               # passphrase-only encryption

Entering the passphrase on the command line (scripts and headless use)

Normally gpg-agent asks for the passphrase through a GUI or terminal pinentry. To supply it non-interactively:

# ~/.gnupg/gpg-agent.conf
allow-loopback-pinentry
gpgconf --kill gpg-agent          # restart the agent to pick up the setting
gpg --batch --pinentry-mode loopback --passphrase-file ~/.gnupg/pass.txt \
    --output out.txt --decrypt file.gpg

Keeping a passphrase in a file defeats much of its purpose. chmod 600 it, and prefer a secrets manager or a dedicated, low-privilege signing key for automation. Do not use --passphrase "secret" on the command line, where it is visible in ps and history.

Cache lifetime for the agent (see also pass):

echo "default-cache-ttl 600" >> ~/.gnupg/gpg-agent.conf
gpg-connect-agent reloadagent /bye         # apply / clear the cache

Manage installed RPM package-signing keys

RPM systems import vendor GPG keys as pseudo-packages named gpg-pubkey. Reference: How to remove RPM package GPG keys.

sudo rpm -qa gpg-pubkey
sudo rpm -q gpg-pubkey --qf '%{NAME}-%{VERSION}-%{RELEASE}\t%{SUMMARY}\n'
sudo rpm --erase --allmatches gpg-pubkey-<version>-<release>

Only remove a key if you are sure no repository you still use is signed with it.