← All cheat sheets

GPG & AGE ENCRYPTION

Plain-text reference · 5 KB. Read it, search it (Ctrl-F) or print it.

GPG KEY GENERATION#

gpg --gen-key                     # Quick generation
gpg --full-gen-key                # Full options (recommended)
# Choose: RSA+RSA, 4096 bits, expiry 2y

gpg --list-keys                   # List public keys
gpg --list-secret-keys            # List private keys
gpg --list-keys --keyid-format=long  # Show key IDs

GPG KEY MANAGEMENT#

# Export keys
gpg --export -a "user@example.com" > public.asc
gpg --export-secret-keys -a "user@example.com" > private.asc

# Import keys
gpg --import public.asc
gpg --import private.asc

# Delete keys
gpg --delete-key "user@example.com"
gpg --delete-secret-key "user@example.com"

# Trust a key
gpg --edit-key "user@example.com"
gpg> trust
# Select trust level (5 = ultimate for your own keys)
gpg> quit

# Generate revocation certificate
gpg --gen-revoke "user@example.com" > revoke.asc

# Revoke a key
gpg --import revoke.asc

GPG ENCRYPTION#

# Symmetric (password-based)
gpg -c file.txt                   # Encrypt with passphrase
gpg -c --cipher-algo AES256 file.txt  # Specify cipher
gpg -d file.txt.gpg               # Decrypt

# Asymmetric (public key)
gpg -e -r "recipient@example.com" file.txt     # Encrypt
gpg -e -r "user1" -r "user2" file.txt          # Multiple recipients
gpg -d file.txt.gpg                             # Decrypt (auto-finds key)

# Encrypt and sign
gpg -se -r "recipient@example.com" file.txt

# Encrypt to stdout
gpg -e -r "recipient" --armor < file.txt > encrypted.asc

# Decrypt from stdin
cat encrypted.asc | gpg -d > decrypted.txt

GPG SIGNING#

# Sign a file (creates .sig)
gpg -s file.txt                   # Binary signature
gpg --clearsign file.txt          # Cleartext signature
gpg -b file.txt                   # Detached signature
gpg --armor -b file.txt           # Detached ASCII signature

# Verify signature
gpg --verify file.txt.sig file.txt
gpg --verify file.txt.asc

GPG AGENT#

# Cache passphrase
gpg-agent --daemon
echo "default-cache-ttl 3600" >> ~/.gnupg/gpg-agent.conf
echo "max-cache-ttl 7200" >> ~/.gnupg/gpg-agent.conf
gpg-connect-agent reloadagent /bye

GPG BEST PRACTICES#

# Use Ed25519 or RSA 4096
# Set key expiration (1-2 years)
# Create subkeys for signing and encryption
# Keep master key offline
# Use strong passphrase
# Backup keys securely
# Publish to keyserver
gpg --keyserver hkps://keys.openpgp.org --send-keys KEY_ID

===================================

AGE - MODERN ENCRYPTION TOOL#


            

INSTALLATION#

# macOS
brew install age

# Linux
apt install age           # Debian/Ubuntu
# Or download from https://github.com/FiloSottile/age

AGE KEY GENERATION#

# Generate X25519 key pair
age-keygen -o key.txt
# Output: public key to stdout, private key to file
# Public key format: age1...
# Private key format: AGE-SECRET-KEY-1...

AGE ENCRYPT / DECRYPT#

# Encrypt to recipient
age -r age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p -o file.age file.txt

# Encrypt to multiple recipients
age -r age1... -r age1... -o file.age file.txt

# Encrypt with recipients file
age -R recipients.txt -o file.age file.txt

# Decrypt
age -d -i key.txt -o file.txt file.age

# Passphrase encryption (symmetric)
age -p -o file.age file.txt       # Encrypt (prompts for passphrase)
age -d -o file.txt file.age       # Decrypt (prompts for passphrase)

# Pipe support
cat file.txt | age -r age1... > file.age
cat file.age | age -d -i key.txt > file.txt

# Armor (ASCII output)
age -r age1... -a -o file.age.txt file.txt

AGE WITH SSH KEYS#

# Encrypt using SSH public key
age -R ~/.ssh/id_ed25519.pub -o file.age file.txt

# Decrypt using SSH private key
age -d -i ~/.ssh/id_ed25519 -o file.txt file.age

# Encrypt using GitHub user's SSH keys
curl https://github.com/username.keys | age -R - -o file.age file.txt

AGE VS GPG COMPARISON#

Feature          | GPG           | age
-----------------|---------------|----------------
Key format       | PGP keys      | X25519/SSH
Complexity       | High          | Minimal
Web of trust     | Yes           | No
Signing          | Yes           | No (use signify)
Symmetric        | Yes           | Yes (passphrase)
SSH key support  | No            | Yes
Config files     | Many          | None
Key management   | Complex       | Simple
Streaming        | Yes           | Yes
Audit            | Complex       | Easy (small codebase)

PRACTICAL WORKFLOWS#

# Encrypt backup
tar czf - /important/data | age -r age1... > backup.tar.gz.age

# Decrypt and extract
age -d -i key.txt backup.tar.gz.age | tar xzf -

# Encrypt for team (age)
age -R team-keys.txt -o secrets.age secrets.env

# Store encrypted secrets in git (age)
age -R .age-recipients -o .env.age .env
echo ".env" >> .gitignore
git add .env.age .age-recipients

# sops integration (age)
export SOPS_AGE_KEY_FILE=~/.config/sops/age/keys.txt
sops -e --age age1... secrets.yaml > secrets.enc.yaml
sops -d secrets.enc.yaml > secrets.yaml

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.