GPG Key Manager
The GPG Key Manager securely stores your GPG and PGP keys for use across your site. You can create, import, update, and delete keys from a single interface, and the stored keys are available for both encryption and decryption operations.
The GPG Key Manager lets you create or import a key once and reuse it throughout your site. Each entry displays the key's name, type (public only, or public and private key pair), expiration date, and MD5 hash. You can use this information to identify keys and detect duplicates.
Generating GPG Keys
You can generate a new GPG/PGP key pair directly in your browser. The key pair is stored encrypted in the GPG Key Manager and ready to use across your site.
When creating keys, enter your full name or a descriptive label for the key, and your email address.
Setting an expiration date is optional. Most GPG and PGP keys are long-lived and do not expire, but you can apply an expiration date if your organization requires periodic key rotation. You can revoke any key at any time. The GPG Key Manager cannot extend a key's expiration date directly; use a GPG/PGP utility and import the updated key.
If you want to protect your private key with a passphrase, enter it now. Leave this blank to create a key without a passphrase.
After generating a key pair, the public key appears first. Copy and save it if you want to keep a local copy.
After saving the new key pair, a popup displays the private key. Download the private key and save it securely.
Files.com encrypts all private keys before storing them, and they cannot be accessed by Files.com employees.
Importing GPG/PGP Keys
When importing an existing key or key pair, enter a name or label for the key. You can paste the key text or use Choose File to upload from your computer.
Paste or upload the public key in the Public Key field.
Paste or upload the private key in the Private Key field.
If your private key is protected by a passphrase, enter it during import. The import fails if the passphrase is incorrect or missing.
The private key must match the corresponding public key before you complete the import.
Expired keys cannot be imported.
Viewing GPG/PGP Keys
The GPG Key Manager table displays each key's name, type, expiration date, and MD5 hash. Use these details to identify keys, confirm validity, and locate duplicates.
Updating GPG/PGP Keys
Updating a key pair replaces both the public and private keys with new ones.
To update an existing key pair, use the Edit option of the key.
The private key must match its corresponding public key. You cannot update them separately.
Expired GPG/PGP Keys
Files.com requires unexpired keys for encryption, signing, and decryption. This includes decrypting files that were encrypted before the key expired. Keys containing expired subkeys are also rejected during processing. Expiration limits when Files.com will use a key; it does not erase the key material or previously encrypted files.
When a GPG key for your account is about to expire, you receive an automated email notification from Files.com titled Failures/Events that may need your attention.
When a key used for auto-encryption or auto-decryption expires, uploads to the affected folders are disabled until the key is replaced.
Updating and Replacing Expired GPG/PGP Keys
Use a GPG/PGP utility to extend the expiration date of the same key, including any expired subkeys, or request an updated key from its provider. If you need to decrypt previously encrypted files, retain and renew the matching private key. A newly generated, unrelated key pair cannot decrypt files encrypted to the old key.
The GPG Key Manager cannot update key expiration dates, but you can update the expiration date on keys generated with Kleopatra (Windows), GPG Tools (Mac), or GnuPG (Linux).
Export the updated key from the GPG tool and import it into the GPG Key Manager. For a key pair, export and import both the updated public and private keys. Disable the auto-encryption or auto-decryption setting that uses the expired key, then re-enable it using the updated key.
Encrypting and Decrypting Files From the Key Manager
You can encrypt or decrypt a single file on demand directly from any key in the manager, without navigating to the file first. Starting from a key preselects it for the operation, so you pick the source file, set the destination and filename, and configure the same options available from the Files tab.
Removing GPG/PGP Keys
Manual deletion from the GPG Key Manager requires removing the key from active encryption or decryption configurations first, so routine key cleanup does not interrupt configured processing.
Key Lifecycle Rules enforce a separate inactivity policy. They remove keys that meet the rule even when a folder still references them. The folder's processing settings remain, and operations requiring the removed key are blocked until a valid replacement is configured.