Generate PGP Keys
Generate a key pair with an expiration date and a revocation certificate ready from day one. For how PGP works and how others verify your public key, see the PGP Encryption Complete Guide.
Key Generation
- Open your PGP software (GPG/Kleopatra on Windows, built-in GPG on Linux/macOS)
- Select "Generate new key pair"
- Choose RSA 4096-bit ā the default on most marketplaces. Ed25519 (ECC) is a smaller, faster modern alternative if your software supports it.
- Enter a pseudonymous name/email ā not your real identity
- Create a strong passphrase (20+ characters)
- Set an expiration date ā choose 1ā2 years, not "never expires." A key with no expiration stays trusted indefinitely even after compromise; renew the expiration before it lapses while you still hold the private key.
- Generate the key pair and back up the private key and passphrase in separate secure locations
Two Steps Most Guides Skip
Expiration: When the date approaches, extend it from your PGP software while you still have the private key and passphrase ā this keeps the same key ID trusted without forcing contacts to re-import a new key. If the key expires before you renew, others' software may refuse to encrypt to it even though nothing was compromised.
Revocation certificate: Immediately after generation, export a revocation certificate for the new key (in Kleopatra: right-click the key ā "Generate revocation certificate"). Store that file separately from the private key ā on different media, in a different location. If the private key is ever lost or compromised, publish the revocation certificate so the world stops trusting that key ID.
Generate the revocation certificate now, not after a breach. Without it, a compromised private key cannot be formally retired ā contacts have no signed signal to stop using it.