7.5. Revoking your key pair

In the unfortunate event that you lose your key pair or feel it has been compromised, you should revoke it.

You can use the revocation certificate that you generated in advance (or at least you should have done so) to invalidate the key pair. Select File → Import keys from file from the Key Management window and choose the ASC file containing your revocation certificate.

If you did not generate the revocation certificate in advance, you can revoke the key on the fly, provided that you still have your key pair and you remember your passphrase. To do so, select the key pair you want to revoke and click on Edit→ Revoke key. This effectively creates a revocation certificate and imports it in one shot. Note that this command does not work in Enigmail 0.96.0 due to a bug.

Send the revoked key to your contacts to warn them not to use it any more. If you published your public key on a keyserver, remember to upload again the revoked key to it.