You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用pass(基于gpg2)创建密钥遇'Unusable public key'报错求助

Troubleshooting "Unusable public key - No assurance key belongs to named user" in Pass/GPG2

I’ve hit this exact error a handful of times working with pass and GPG, so let’s walk through the fixes that usually resolve it—even when you think you’ve locked in the trust settings correctly.

First, Double-Check Your GPG Trust Settings (Really)

Sometimes setting the trust level to ultimate doesn’t stick if you skip saving the changes. Here’s how to confirm and fix it:

  • Run gpg2 --edit-key [your-key-id-or-email]
  • In the interactive prompt, type trust and press Enter
  • Select option 5 (I trust ultimately) and confirm your choice
  • Type save to exit and apply the changes
  • Verify it worked with gpg2 --list-keys --with-colons | grep trust—you should see trust:u next to your key (the u stands for ultimate trust)

Ensure Pass Is Using the Correct Key

Pass relies on the ~/.password-store/.gpg-id file to know which key to use. It’s easy for this to point to an old or mismatched key:

  • Open ~/.password-store/.gpg-id in a text editor
  • Make sure the key ID or email matches exactly the one you set to ultimate trust
  • Save the file if you made any changes

Refresh GPG Agent’s Cache

GPG agent sometimes caches outdated trust data, causing this error even after you update settings:

  • Kill the agent with gpgconf --kill gpg-agent
  • Restart your terminal or run gpg-agent --daemon to reload it

Verify Key User ID Match

Pass can be finicky about exact matches between the key’s user ID and what you’re using. Check:

  • Run gpg2 --list-keys and look at the uid line for your key (e.g., uid [ultimate] Jane Doe <jane@example.com>)
  • Make sure the name/email here matches exactly what you use with pass—no typos, extra spaces, or case differences allowed

Test GPG Directly to Isolate the Issue

Rule out Pass-specific problems by testing GPG encryption/decryption manually:

  • Create a test file: echo "test content" | gpg2 -e -r [your-key-id] -o test.gpg
  • Decrypt it: gpg2 -d test.gpg
    • If this works, the issue is likely with Pass configuration (double-check .gpg-id again)
    • If this fails, your GPG key still has trust/validation issues—loop back to the first step to reconfirm trust settings

Should You Generate a New Key?

Only do this if all the above steps fail. Generating a new key is a last resort, but here’s how to do it safely:

  1. Run gpg2 --full-generate-key
    • Choose RSA (default is fine), set key length to 4096 for better security
    • Set an expiration date (even if it’s far in the future—good practice for key management)
    • Enter your name and email to match what you use with pass
  2. Backup your new key immediately: Run gpg2 --export-secret-keys --armor [your-new-key-id] > private-key-backup.asc and store this somewhere secure (offline if possible)
  3. Update ~/.password-store/.gpg-id to use your new key ID
  4. Re-encrypt your existing password store if needed (pass will prompt you to re-encrypt when you next use it, or you can run pass init [new-key-id])

内容的提问来源于stack exchange,提问作者MonoGenerator

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:27:19