使用pass(基于gpg2)创建密钥遇'Unusable public key'报错求助
I’ve hit this exact error a handful of times working with pass and GPG, so let’s walk through the fixes that usually resolve it—even when you think you’ve locked in the trust settings correctly.
First, Double-Check Your GPG Trust Settings (Really)
Sometimes setting the trust level to ultimate doesn’t stick if you skip saving the changes. Here’s how to confirm and fix it:
- Run
gpg2 --edit-key [your-key-id-or-email] - In the interactive prompt, type
trustand press Enter - Select option 5 (I trust ultimately) and confirm your choice
- Type
saveto exit and apply the changes - Verify it worked with
gpg2 --list-keys --with-colons | grep trust—you should seetrust:unext to your key (theustands for ultimate trust)
Ensure Pass Is Using the Correct Key
Pass relies on the ~/.password-store/.gpg-id file to know which key to use. It’s easy for this to point to an old or mismatched key:
- Open
~/.password-store/.gpg-idin a text editor - Make sure the key ID or email matches exactly the one you set to ultimate trust
- Save the file if you made any changes
Refresh GPG Agent’s Cache
GPG agent sometimes caches outdated trust data, causing this error even after you update settings:
- Kill the agent with
gpgconf --kill gpg-agent - Restart your terminal or run
gpg-agent --daemonto reload it
Verify Key User ID Match
Pass can be finicky about exact matches between the key’s user ID and what you’re using. Check:
- Run
gpg2 --list-keysand look at theuidline for your key (e.g.,uid [ultimate] Jane Doe <jane@example.com>) - Make sure the name/email here matches exactly what you use with pass—no typos, extra spaces, or case differences allowed
Test GPG Directly to Isolate the Issue
Rule out Pass-specific problems by testing GPG encryption/decryption manually:
- Create a test file:
echo "test content" | gpg2 -e -r [your-key-id] -o test.gpg - Decrypt it:
gpg2 -d test.gpg- If this works, the issue is likely with Pass configuration (double-check
.gpg-idagain) - If this fails, your GPG key still has trust/validation issues—loop back to the first step to reconfirm trust settings
- If this works, the issue is likely with Pass configuration (double-check
Should You Generate a New Key?
Only do this if all the above steps fail. Generating a new key is a last resort, but here’s how to do it safely:
- Run
gpg2 --full-generate-key- Choose RSA (default is fine), set key length to 4096 for better security
- Set an expiration date (even if it’s far in the future—good practice for key management)
- Enter your name and email to match what you use with pass
- Backup your new key immediately: Run
gpg2 --export-secret-keys --armor [your-new-key-id] > private-key-backup.ascand store this somewhere secure (offline if possible) - Update
~/.password-store/.gpg-idto use your new key ID - Re-encrypt your existing password store if needed (pass will prompt you to re-encrypt when you next use it, or you can run
pass init [new-key-id])
内容的提问来源于stack exchange,提问作者MonoGenerator

