SECURITY

Generate Your PGP Keys

Generate Your PGP Keys

Generate PGP Keys

Generate a key pair with an expiration date and a revocation certificate ready from day one. For how PGP works and how others verify your public key, see the PGP Encryption Complete Guide.

Key Generation

  1. Open your PGP software (GPG/Kleopatra on Windows, built-in GPG on Linux/macOS)
  2. Select "Generate new key pair"
  3. Choose RSA 4096-bit — the default on most marketplaces. Ed25519 (ECC) is a smaller, faster modern alternative if your software supports it.
  4. Enter a pseudonymous name/email — not your real identity
  5. Create a strong passphrase (20+ characters)
  6. Set an expiration date — choose 1–2 years, not "never expires." A key with no expiration stays trusted indefinitely even after compromise; renew the expiration before it lapses while you still hold the private key.
  7. Generate the key pair and back up the private key and passphrase in separate secure locations

Two Steps Most Guides Skip

Expiration: When the date approaches, extend it from your PGP software while you still have the private key and passphrase — this keeps the same key ID trusted without forcing contacts to re-import a new key. If the key expires before you renew, others' software may refuse to encrypt to it even though nothing was compromised.

Revocation certificate: Immediately after generation, export a revocation certificate for the new key (in Kleopatra: right-click the key → "Generate revocation certificate"). Store that file separately from the private key — on different media, in a different location. If the private key is ever lost or compromised, publish the revocation certificate so the world stops trusting that key ID.

Generate the revocation certificate now, not after a breach. Without it, a compromised private key cannot be formally retired — contacts have no signed signal to stop using it.