GnuPG 2.5.21
GnuPG is the free implementation of the OpenPGP standard, providing encryption, signing, and key management for files, email, and software distribution.
Download TAR.BZ2 Project website ↗Download Mirrors
GnuPG implements the OpenPGP standard, and it is the reason you can verify that a downloaded tarball came from the person who claims to have released it.
Branch status
The 2.4.x branch reached end of life on June 30, 2026. The 2.5.x series is now stable and also serves as the development branch, which is an unusual arrangement and worth knowing if you were tracking 2.4 expecting continued support.
What people actually use it for
Three things dominate, and only one of them is email.
Verifying downloads. Nearly every serious open-source project signs its releases. This is the most common legitimate use of GnuPG and the one most worth learning.
# Import the signing key, then verify
gpg --recv-keys KEYID
gpg --verify file.tar.xz.sig file.tar.xz
Signing your own work. Git commit signing, package signing, and release signing all run through GnuPG.
git config --global user.signingkey YOURKEYID
git config --global commit.gpgsign true
Encrypting files. Less common, but the tool is there.
gpg --symmetric --cipher-algo AES256 secrets.txt # passphrase only
gpg --encrypt --recipient alice@example.com file # to someone's public key
Key management basics
# Generate a key with sensible defaults
gpg --full-generate-key
# List what you have
gpg --list-secret-keys --keyid-format LONG
# Export a public key to share
gpg --armor --export YOURKEYID
# Always generate a revocation certificate and store it somewhere safe
gpg --output revoke.asc --gen-revoke YOURKEYID
That last one is the step people skip and regret. Without a revocation certificate, a lost or compromised key cannot be marked invalid, and it stays on keyservers looking valid indefinitely.
The honest assessment
GnuPG’s user experience is difficult and has been for decades. The threat model it was designed for is specific, and the interface reflects a 1990s understanding of how people would use cryptography.
For verifying downloads and signing commits, it is excellent and worth the learning curve. For encrypted messaging between people, modern tools built for that purpose are a better choice.
Our GPG basics guide covers the practical workflows.
Verify Your Download
GnuPG releases are signed, and the signing keys are published on the download page. The bootstrapping problem is real: verify against a key you already trust, or obtain the first copy through your distribution.