PreviousNext
Help > 8.2.1 Creating OpenPGP Keys 
8.2.1 Creating OpenPGP Keys 

OpenPGP is a non-proprietary protocol for encrypting e-mail with the use of public-key cryptography based on PGP. It defines standard formats for encrypted messages, signatures, private keys, and certificates for exchanging public keys.

Click Applications › Utilities › Passwords and Keys.

Click File › New.

Select PGP Key and click Continue.

Specify your full name and e-mail address.

Click Advanced key options to specify the following advanced options for the key.

Comment

An optional comment.

Encryption Type

Specifies the encryption algorithms used to generate your keys. DSA ElGamal is the recommended choice because it lets you encrypt, decrypt, sign, and verify as needed. Both DSA (sign only) and RSA (sign only) allow only signing.

Key Strength

Specifies the length of the key in bits. The longer the key, the more secure it is (provided a strong passphrase is used). Keep in mind that performing any operation with a longer key requires more time than it does with a shorter key. Acceptable values are between 1024 and 4096 bits. At least 2048 bits are recommended.

Expiration Date

Specifies the date at which the key will cease to be usable for performing encryption or signing operations. You will need to either change the expiration date or generate a new key or subkey after this amount of time passes. Sign your new key with your old one before it expires to preserve your trust status.

Click Create to create the new key pair.

The Passphrase for New PGP Key dialog opens.

Specify the passphrase twice for your new key, then click OK.

When you specify a passphrase, use the same practices you use when you create a strong password.