GPG (GNU Privacy Guard): Encryption and Key Management
GPG, or GNU Privacy Guard, is a free and open-source implementation of the OpenPGP standard. It allows you to encrypt and decrypt your data and communications, create digital signatures, and manage cryptographic keys. GPG is a powerful tool for ensuring data confidentiality, integrity, and authenticity.
1. Symmetric Encryption (Encrypting with a Passphrase)
Symmetric encryption uses a single passphrase to both encrypt and decrypt a file. This method is suitable for encrypting files for personal use or when you can securely share the passphrase with the recipient.
gpg --symmetric --cipher-algo AES256 my-creds.xlsx--symmetric: Instructs GPG to use symmetric-key encryption.--cipher-algo AES256: Specifies the AES256 algorithm for encryption (recommended).- GPG will prompt you to enter and confirm a passphrase.
This command will create an encrypted file named my-creds.xlsx.gpg and will keep the original file. It is crucial to delete the original unencrypted file securely after encryption if it contains sensitive data.
2. Public/Private Key Encryption (Asymmetric Encryption)
Asymmetric encryption uses a pair of mathematically linked keys: a public key and a private key. The public key can be freely shared and is used to encrypt data for you. Only your corresponding private key can decrypt that data.
Generate a Public/Private Key Pair
This command guides you through the process of creating your own GPG key pair.
gpg --full-generate-keyYou will be asked to choose the key type, key size, expiration, and then provide your real name, email address, and an optional comment. It’s important to use a strong passphrase to protect your private key.
List GPG Private (Secret) Keys
To view your private keys and their details, including the full fingerprint.
gpg --list-secret-keys --keyid-format LONGExample Output Snippet:
sec rsa4096/0123456789ABCDEF 2025-05-16 [SC]
0123456789ABCDEF0123456789ABCDEF01234567
uid [ultimate] Example User <[email protected]>
ssb rsa4096/FEDCBA9876543210 2025-05-16 [E]
The long hexadecimal string (e.g., 0123456789ABCDEF) is the key ID or fingerprint, which uniquely identifies your key.
List GPG Public Keys
To view your public keys that are stored in your keyring.
gpg --list-keys --keyid-format LONGExport a Public Key
Share your public key with others so they can encrypt files for you.
gpg --export --armor <key_ID_or_email> > recipient-public.key
# Example:
gpg --export --armor 0123456789ABCDEF > bob-public.key--armor: Outputs the key in ASCII armored format, making it suitable for email or text transfer.
Import a Public Key
To decrypt files encrypted by someone else, you first need to import their public key into your keyring.
gpg --import bob-public.keyExport a Private (Secret) Key
You might need to export your private key if you are moving it to another machine or backing it up. Handle with extreme care, as anyone with this file and your passphrase can impersonate you or decrypt your data.
gpg --export-secret-keys --armor <key_ID_or_email> > my-private.key
# Example:
gpg --export-secret-keys --armor 0123456789ABCDEF > my-private.key3. Encrypting and Decrypting with Public Keys
Encrypt a File for a Recipient
To encrypt a file so that only a specific recipient can decrypt it, you use their public key.
gpg --encrypt -r <recipient_key_ID_or_email> file.txt
# Example:
gpg --encrypt -r 0123456789ABCDEF sensitive_data.txt-r <recipient_key_ID_or_email>: Specifies the recipient’s public key that GPG should use for encryption.
This creates file.txt.gpg.
Decrypt a File
To decrypt a file that was encrypted using your public key. GPG automatically identifies the correct private key from your keyring.
gpg --decrypt file.gpgThis command will output the decrypted content to stdout. To save it to a file:
gpg --decrypt file.gpg > decrypted_file.txtGPG is able to find the correct private key for decryption based on metadata embedded in the encrypted file, so you typically do not need to specify it. You will be prompted for your private key’s passphrase.
4. Full Workflow Example: Secure Communication
This outlines the steps for Person A to securely send a file to Person B using GPG.
- Person B: Generates their own GPG key pair (
gpg --full-generate-key). - Person B: Exports their public key (
gpg --export --armor <B's_key_ID> > B_public.key). - Person B: Securely sends
B_public.keyto Person A. - Person A: Imports Person B’s public key into their keyring (
gpg --import B_public.key). - Person A: Encrypts the sensitive file using Person B’s public key (
gpg --encrypt -r <B's_key_ID> sensitive.txt). - Person A: Sends the encrypted file (
sensitive.txt.gpg) to Person B. - Person B: Decrypts the file using their own private key (
gpg --decrypt sensitive.txt.gpg). Person B will be prompted for their private key’s passphrase.