Encrypting Files and Email on elementary OS with GnuPG
GnuPG, commonly shortened to GPG, gives elementary OS users a mature way to protect files and verify digital signatures. It uses strong public-key cryptography for sharing documents, while its symmetric mode can secure a local archive with a password. Because GnuPG is available from standard Linux repositories, it fits naturally into an elementary OS workflow without requiring a commercial encryption service.
File encryption is useful for tax records, identity documents, private photographs, client material and backups. Email encryption has a different purpose: it protects message contents while they travel between mail systems, provided the sender and recipient have configured compatible OpenPGP keys. Understanding that distinction helps you choose the right method instead of treating every confidential file as an email attachment.
Why GnuPG Fits The elementary OS Desktop
GnuPG is a command-line tool, but it does not require you to work in a command-line-only environment. You can use elementary OS Files to locate documents, Terminal to apply encryption commands, and a graphical email client with OpenPGP support for correspondence. This combination is lightweight and works well on older laptops as well as current hardware.
Public-key encryption uses two related keys. The public key can be shared freely and is used by other people to encrypt files for you or verify your signatures. The private key stays secret on your computer and is used to decrypt material or create signatures. A passphrase protects the private key if someone obtains a copy of the keyring.
There is also a simpler option called symmetric encryption. You provide a password, and GnuPG uses that password to encrypt and decrypt the file. This is convenient when you are securing a document for yourself or sharing it with someone through a separate, trusted channel. Public-key encryption is generally easier for ongoing collaboration because you do not need to exchange the same secret password.
Encryption does not solve every privacy problem. A filename can reveal information, email subjects and recipient addresses are usually visible, and a compromised computer can expose files after you unlock them. GnuPG is one part of a broader security practice that includes system updates, a strong login password and carefully protected backups.
Installing And Checking GnuPG
Open Terminal from the Applications menu and install the package supplied by the Ubuntu base used by your elementary OS release:
sudo apt update
sudo apt install gnupg
On many installations, GnuPG is already present because another application depends on it. The package manager will say so if there is nothing new to install. Confirm that it works with:
gpg --version
The output shows the installed GnuPG release and supported algorithms. You can also inspect the location of the executable:
command -v gpg
The result is normally /usr/bin/gpg. Avoid downloading a random executable or shell script from a search result. Using the distribution repository gives you a package managed through the normal elementary OS update process.
Create a private working directory for encrypted material if you want to keep your files organised:
mkdir -p ~/Documents/Encrypted
chmod 700 ~/Documents/Encrypted
The chmod command limits access to that directory for your user account. It does not encrypt the directory; it simply reduces accidental access by other local accounts. If you use a shared family computer, a workplace laptop or a machine repaired by a third party, full-disk encryption and a separate user account remain important.
Creating A Personal OpenPGP Key
Generate a key pair with:
gpg --full-generate-key
GnuPG will ask for the key type, size, expiry and identity details. The default RSA and RSA choice is broadly compatible. A 3072-bit or 4096-bit key is suitable for long-term personal use, although the default offered by a current release is generally reasonable. Setting an expiry date, such as two years, encourages regular review; it does not automatically destroy the key when the date arrives.
Use the name and email address that recipients will recognise. The email address should match the address from which you normally send encrypted messages, but avoid adding unnecessary personal information to the identity. Choose a long, unique passphrase. A sequence of several unrelated words is often easier to remember than a short complex password, especially when you need to unlock the key after a system restart.
List your public keys:
gpg --list-keys
List private keys separately:
gpg --list-secret-keys
Each key has a long hexadecimal fingerprint. Display it clearly with:
gpg --fingerprint
The fingerprint is the reliable identity check. If a friend or colleague gives you a public key, compare its fingerprint with a value received through a separate channel, such as a phone call or an in-person conversation. Do not assume that a key found on a public server belongs to the person named on it.
Export your public key when you need to share it:
gpg --armor --export your-email@example.com > my-public-key.asc
The --armor option creates readable ASCII text, which is convenient for an attachment or a forum post. Never export your private key for ordinary sharing. A file produced with --export-secret-keys contains the ability to decrypt your protected material and sign messages.
Encrypting Files For Yourself Or Others
For a file that you want to protect with a password, use symmetric encryption:
gpg --symmetric --cipher-algo AES256 report.pdf
GnuPG creates report.pdf.gpg and asks for a passphrase. The original file remains in place, so delete it securely from the working folder when appropriate. On solid-state drives, ordinary deletion does not guarantee that old data cannot be recovered. Full-disk encryption is a better defence for the whole device; the GPG copy protects the file when it is stored or transferred separately.
To decrypt the file later:
gpg --output report.pdf --decrypt report.pdf.gpg
For public-key encryption, first import the recipient’s verified public key:
gpg --import alex-public-key.asc
Then encrypt a document for Alex:
gpg --output proposal.pdf.gpg --encrypt --recipient alex@example.com proposal.pdf
Only Alex’s corresponding private key can decrypt that result. If you also want Alex to verify that the file came from you and was not changed, add your own identity with --sign:
gpg --output proposal.pdf.gpg --encrypt --sign --recipient alex@example.com proposal.pdf
The recipient must have your public key to verify the signature. For a file encrypted for several people, include each recipient:
gpg --output minutes.pdf.gpg --encrypt \
--recipient alex@example.com \
--recipient casey@example.com \
minutes.pdf
Keep the original filename and the .gpg version separate until you have tested decryption. A common mistake is to encrypt a file, delete the original, then discover that the wrong recipient key was selected or that the passphrase was forgotten. Encryption protects data from unauthorised access, but it cannot recover a lost private key or an irretrievable password.
Decrypting, Signing And Managing Keys
When someone sends you a GPG file, save it with Files or your browser and decrypt it in Terminal:
gpg --output received.pdf --decrypt received.pdf.gpg
GnuPG will check the file’s integrity and, when applicable, report a valid signature. A successful decryption does not automatically mean the sender is trustworthy. If the file was encrypted to your key but signed by an unknown key, verify the signer’s fingerprint before relying on its contents.
Digital signatures are useful even when a file does not need secrecy. Sign a file in a separate signature file with:
gpg --armor --detach-sign invoice.pdf
This creates invoice.pdf.asc. The recipient needs your public key and can check the signature with:
gpg --verify invoice.pdf.asc invoice.pdf
A signature confirms that the file matches what was signed and that it was created by the holder of the private key. It does not encrypt the document.
Back up your private key and revocation certificate before relying on the key for important work. Create a revocation certificate with:
gpg --output revoke-my-key.asc --gen-revoke your-email@example.com
Store it offline in a secure location. Export a protected backup of your secret key to removable media:
gpg --armor --export-secret-keys your-email@example.com > private-key-backup.asc
Treat that backup like a master key. Keep it encrypted, limit physical access and avoid leaving it in an ordinary cloud-synchronisation folder. A backup that is available to every device and service you use may become the easiest part of your security setup to steal.
Using GnuPG With Email
Email encryption needs both parties to use compatible OpenPGP tools. Install a mail application that supports OpenPGP directly, such as a current Thunderbird package, and configure your account normally. Thunderbird can create or use an existing OpenPGP key, encrypt messages and attachments, and validate signatures. The exact menus can vary between releases and between a native package and a Flatpak.
The elementary OS desktop includes a simple, focused application set, but its default mail experience may not provide full OpenPGP controls. Check the capabilities of the mail client you install rather than assuming that an email application can encrypt merely because GnuPG is installed. If you use a Flatpak application, its file-access permissions may affect where it can read your exported key or attachment. The file chooser is usually the safest way to grant access without opening your entire home directory.
To send an encrypted message, import and verify the recipient’s public key first. Select encryption in the email client and confirm that a key is available for every recipient. You can also sign the message with your private key. Recipients need your public key to validate the signature, while they need their own private key to read mail encrypted for them.
OpenPGP generally protects the message body and attachments, but it does not hide the sender, recipient, time, routing information or subject line. Avoid placing sensitive information in the subject. Encryption may also be weakened if the recipient’s computer is infected, if messages are forwarded in plain text, or if the recipient’s mail client stores decrypted copies without device protection.
For Australian users, this matters when sending documents over NBN connections, public Wi-Fi in Sydney or Melbourne, or a shared connection in a household. Encryption reduces exposure while a message is being transported, but a secure device and a trusted recipient remain necessary. The Privacy Act 1988 and the Australian Privacy Principles require many organisations to take reasonable steps to protect personal information, although they do not mandate GnuPG for every email. Businesses should treat OpenPGP as one possible safeguard within their own privacy and records-handling policies.
Practical Workflows For Australian Users
A sole trader in Brisbane might use symmetric GPG encryption for a local archive of invoices and tax documents, then keep that archive on an encrypted external drive. A community group in Adelaide could use public-key encryption to exchange membership spreadsheets without emailing an unprotected attachment. A university student in Perth might sign a research file so a supervisor can detect accidental changes. These workflows use the same tool but different security goals.
Australian work often involves remote collaboration across time zones, contractors and cloud services. A small business may operate from a home office in Canberra while sending documents to an accountant in Sydney. Before using public-key encryption, agree on key fingerprints, file naming and a second communication channel for urgent verification. Do not rely on an email address alone to identify a key.
For larger files, encrypt the file first and send the resulting .gpg attachment through the normal mail system. If the attachment is too large, place the encrypted file in a trusted storage service and share the download link separately. The storage provider can see the file exists and may see its size, but cannot read the contents without the required key or passphrase.
Be careful with government identity documents, health information and customer records. The Australian Privacy Principles, state and territory obligations, professional rules and contractual requirements can all affect how information should be stored and shared. GnuPG does not replace retention policies, access controls or secure disposal. It gives you a strong technical layer for the file itself.
Common Problems And Safer Habits
The most frequent error is encrypting to the wrong public key. Before sending, inspect the key identity and fingerprint, and use a test file with the recipient. Another common problem is forgetting that a file encrypted only to someone else cannot be opened by you. Add your own public key as a recipient when you need to retain an accessible copy.
If GnuPG reports No public key, import the recipient’s key and confirm its identity. If it reports decryption failed, check that the private key is present and that you entered the correct passphrase. If a graphical program cannot see a key, restart it after importing the key, confirm that it uses the same home directory, and check whether its Flatpak sandbox can access the relevant files.
Keep elementary OS and GnuPG updated through normal software updates. Use a separate key for testing only if you regularly experiment with scripts or integrations. Never paste a private key or passphrase into a forum post, support ticket or chat. When using Terminal, remember that command history can retain filenames and options, so avoid placing passwords directly in commands.
The essential habits are simple: verify fingerprints, protect the private key, maintain a tested backup, encrypt before uploading or sending, and remember that metadata and endpoints still matter. GnuPG is most effective when it becomes a predictable part of your file and email routine rather than an emergency tool used once.
GnuPG brings reliable OpenPGP encryption to elementary OS with very little overhead. Symmetric encryption protects standalone files, public-key encryption supports collaboration, and digital signatures establish whether content has changed. The detail to remember is that your public key may travel freely, but your private key and its passphrase must remain under your control.