The Encryption interface in cPanel allows you to create, store, and manage GnuPG keys for secure email communication. GnuPG uses public key cryptography, meaning messages encrypted with a public key can only be decrypted by the private key holder, ensuring your emails remain secure and private.
This guide walks you through creating new encryption keys, importing existing keys, and managing your key pairs in your OBHost hosting account.
What Are GnuPG Encryption Keys?
GnuPG (GNU Privacy Guard) keys use public key encryption to secure your communications. When someone sends you an encrypted message, they use your public key to encrypt it. Only you, with the corresponding private key, can decrypt and read that message.
This two-key system provides strong security for email communications and file transfers. The public key can be shared freely with anyone who wants to send you encrypted messages, while your private key must be kept secure and never shared.
How to Create a New GnuPG Key
Creating a new encryption key in cPanel is straightforward. Follow these steps:
- Log into your cPanel account
- Navigate to the Encryption interface under the Security section
- Enter your information in the Create a New Key fields including your name and email address
- Create a strong password for your key (use a combination of uppercase and lowercase letters, numbers, and symbols)
- Select an expiration date for your key (the default is one year)
- Choose your key size from the Key Size dropdown menu (2048 bits is the default and recommended minimum)
- Click Generate Key
Once created, you can export this key and add it to email clients or other programs that support GnuPG encryption.
Recommended Key Settings
For maximum security, use at least 2048-bit key size. Larger keys (4096 bits) provide stronger encryption but may take longer to generate and use. Set an appropriate expiration date for your keys, typically one year, to maintain good security practices.
How to Import an Existing GnuPG Key
If you already have a GnuPG key from another system or email client, you can import it into your cPanel account:
- Locate your existing GnuPG key block (typically starts with "BEGIN PGP PUBLIC KEY BLOCK" or "BEGIN PGP PRIVATE KEY BLOCK")
- Copy the entire key block including the begin and end markers
- In the cPanel Encryption interface, find the Import Key section
- Paste your key into the text box
- Click Import
The system will add the imported key to your server, making it available for use with your hosting account.
Managing Your Encryption Keys
After creating or importing keys, you can view and manage them in the Public Keys and Private Keys tables within the Encryption interface.
How to View a Key
To view the details of any stored key:
- Find the key in either the Public Keys or Private Keys table
- Click View next to the key
- The interface will display the complete key block
- Click Go Back to return to the main Encryption interface
How to Delete a Key
To remove a key from your server:
- Locate the key you want to delete in the appropriate table
- Click Delete GnuPG Key for that key
- Confirm by clicking Yes in the confirmation dialog
Important: You must delete the private key before deleting its corresponding public key. Attempting to delete a public key while the private key still exists will result in an error.
Using Encryption Keys with Email Clients
Once you've created or imported your GnuPG keys, you'll need to configure your email client to use them. Most popular email programs support PGP/GnuPG encryption, including:
- Apple Mail (macOS and iOS)
- Microsoft Outlook
- Mozilla Thunderbird
- eM Client
- Gmail (with browser extensions)
Each email client has specific steps for installing and using encryption keys. Consult your email program's documentation for detailed instructions on importing your GnuPG keys and enabling encrypted email.
Best Practices for Encryption Key Management
Follow these security guidelines when working with encryption keys:
- Use strong passwords: Your key password should be complex and unique, combining uppercase and lowercase letters, numbers, and special characters
- Backup your private key: Store a secure backup of your private key in a safe location. If you lose it, you won't be able to decrypt messages sent to you
- Never share your private key: Only share your public key with others. Your private key must remain confidential
- Set expiration dates: Keys should expire after a reasonable period (typically one year) to maintain security
- Keep software updated: Ensure your email client and encryption software are up to date with the latest security patches
Frequently Asked Questions
What's the difference between public and private keys?
Your public key is meant to be shared with anyone who wants to send you encrypted messages. Your private key must be kept secret and is used to decrypt messages that were encrypted with your public key. Think of the public key as a padlock anyone can use to lock a message, and the private key as the only key that can unlock it.
What key size should I use for my GnuPG keys?
A 2048-bit key is the minimum recommended size and provides adequate security for most users. For enhanced security, you can use a 4096-bit key, though it will take longer to generate and may slightly slow down encryption and decryption operations. Never use keys smaller than 2048 bits.
Can I use the same encryption key on multiple devices?
Yes, you can export your GnuPG key and import it into multiple email clients or devices. However, be careful when transferring your private key. Always use secure methods to move your private key between devices, and consider using a strong password to protect the key file during transfer.
What happens if I forget my key password?
Unfortunately, if you forget the password for your private key, there is no way to recover it. You will need to generate a new key pair and distribute your new public key to your contacts. This is why it's crucial to use a memorable but secure password and store it safely.
Need help setting up encryption keys or have questions about secure email? OBHost's support team is available 24/7 to assist you. Visit our contact page or email us at support@obhost.org for technical assistance.