whatis gpg
GPG (GnuPG)
Also known as: GnuPG, PGP, OpenPGP
GNU Privacy Guard, the OpenPGP tool used to encrypt files and to sign and verify software, packages, and Git commits.
What Is GPG (GnuPG) in Linux?
GPG uses public-key cryptography. Anyone can encrypt to your public key or verify your signatures, while only your private key decrypts and signs.
On Linux its biggest everyday job is invisible: package managers verify every downloaded package against the distro's GPG keys. You also use it to verify ISO downloads and in tools like pass and SOPS.
Example
gpg --verify ubuntu.iso.gpg SHA256SUMS
gpg -c secrets.txt Learn more about GPG (GnuPG)
- GPG Basics on Linux GPG provides encryption and digital signatures using public-key cryptography, and it underlies how Linux package repositories verify software has not been tampered with. This guide covers generating a key pair, encrypting and decrypting files, and signing and verifying.
- pass: The Unix Password Manager How pass stores each secret as a GPG-encrypted file in a Git repository, why that design is durable, and the honest limitations of using it on a phone.
- Secrets in Git with sops and age How to commit encrypted secrets alongside your code without committing plaintext, why sops encrypts values and not whole files, and how age replaced GPG for this job.
Related tools
- GPG Command Builder Verify signed downloads, generate keys, and sign files or git commits without guessing flags.