gpg - OpenPGP encryption and signing tool
gpg [OPTIONS] [FILE]
Options you will use
--dearmor- Convert ASCII-armored input (-----BEGIN PGP PUBLIC KEY BLOCK-----) to the binary format. How you turn a repo Release.key into the keyring file apt's signed-by= expects.
--enarmor- The reverse: binary to ASCII armor.
-o, --output FILE- Write the output to FILE.
-a, --armor- Create ASCII-armored output.
--import- Import keys into your keyring.
--export- Export keys from your keyring.
-k, --list-keys- List the public keys in the keyring.
--fingerprint- List keys with their fingerprints - compare it with the one the vendor publishes.
--show-keys- Show the keys in a file without importing them.
--verify- Check a signature (detached: gpg --verify file.sig file).
-d, --decrypt- Decrypt (and verify) the input.
-e, --encrypt- Encrypt for the recipients given with -r.
-r, --recipient NAME- Encrypt for this user id or key.
-s, --sign- Make a signature.
--recv-keys KEYID- Import keys from a keyserver.
--keyserver NAME- The keyserver to use.
--no-default-keyring- Do not use ~/.gnupg/pubring.kbx.
--keyring FILE- Use FILE as a keyring.
--batch- Never ask; for scripts.
--yes- Assume yes, e.g. to overwrite the output file.
Gotchas
- apt keyrings:
curl -fsSL URL/Release.key | sudo gpg --dearmor -o /etc/apt/keyrings/NAME.gpg, thendeb [signed-by=/etc/apt/keyrings/NAME.gpg] .... apt-key is deprecated.
Try gpg in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.