Skip to main content

Encrypt and Decrypt Files with PGP

Configuration → Settings → Certificates

Use PGP keys to protect CSV files in transit: decrypt files sent to NIM, or encrypt and sign files NIM sends to a trusted recipient.

PGP encryption uses a public/private key pair. NIM stores the keys in its certificate repository. The important rule is simple: public keys can be shared; private keys must stay with their owner.

Protect private keys

Never send a private PGP key through email, HTTP, unsecured FTP, tickets, or shared file locations. Store and exchange it only through your organization’s approved secure process.

Choose the workflowDirect link to Choose the workflow

What you need to doKey NIM needsKey to shareWhere to configure it
Decrypt an encrypted CSV file sent to NIMNIM’s private keyNIM’s matching public key goes to the sending partyCSV-File or CSV-File-SFTP connector
Encrypt a CSV file NIM sends outRecipient’s public keyThe recipient keeps their private keyExport task or multi-export task
Sign a CSV file NIM sends outNIM’s private keyNIM’s matching public key goes to the recipientExport or multi-export task

Generate a key pair for NIMDirect link to Generate a key pair for NIM

Generate a NIM-owned key pair when another party needs to encrypt files that NIM will decrypt, or when NIM needs to sign outgoing files.

  1. Go to Configuration → Settings → Certificates.

  2. Select Generate PGP key.

  3. Complete the key details:

    FieldGuidance
    Certificate nameUse a descriptive name that identifies the file exchange and owner, such as HR-Partner-Inbound-2026.
    Primary key algorithmChoose the algorithm required by your organization or file-exchange partner.
    ExpirationOptionally set an expiration using a number plus y, m, w, or d; for example, 3w means three weeks.
    User IDsIdentify the person or organization that owns the key.
    SubkeysOptionally add, remove, or set expiration for subkeys according to your key-management policy.

  1. Select Generate. The key appears in the certificate list.
Record the owner and expiryDocument the key’s purpose, external partner, owner, and expiry date before it is used in a production import or export.

Share NIM’s public key for inbound encryptionDirect link to Share NIM’s public key for inbound encryption

When a partner must send NIM an encrypted file, export and provide them only the public portion of NIM’s key:

  1. Go to Configuration → Settings → Certificates.
  2. Find the NIM-owned PGP key.
  3. Select its export button to download the public key.

  1. Send the public key to the partner through an approved channel. They use it to encrypt the file; NIM uses its private key to decrypt the received file.

Import a recipient’s public key for outbound encryptionDirect link to Import a recipient’s public key for outbound encryption

When NIM must encrypt files before sending them to another party, obtain that party’s public PGP key.

  1. Verify the key’s owner and fingerprint through your organization’s approved process.
  2. Go to Configuration → Settings → Certificates and select Add.
  3. Enter a descriptive name, select the recipient’s public key file, provide a password if required, and select Add.
  4. Configure the selected public key in the export task or multi-export task.
  5. Run a controlled export and confirm the recipient can decrypt the resulting file.

Configure encrypted file exchangeDirect link to Configure encrypted file exchange

Encrypted inbound CSV filesDirect link to Encrypted inbound CSV files

Configure the CSV-File or CSV-File-SFTP connector to use the NIM-owned private PGP key. Test with a non-production encrypted file from the sender before scheduling collection.

Encrypted and signed exportsDirect link to Encrypted and signed exports

In an export or multi-export task, enable PGP file encryption and select the recipient’s public key. If the recipient must validate that NIM produced the file, also select the appropriate NIM private key for signing.

Export tasks can produce armored output (.asc) or binary output (.gpg). Agree on the expected format with the receiving party before automating transfer.

Operate PGP keys safelyDirect link to Operate PGP keys safely

  • Confirm the key owner and purpose before importing a public key or sharing one of NIM’s public keys.
  • Monitor expiration and rotate keys before a scheduled import or export fails.
  • Test a replacement key with a controlled file before retiring the previous key.
  • Remove retired keys only after every dependent connector, export task, and file-exchange partner uses the replacement.
  • Use the certificate expiration notification tutorial to monitor key lifecycles alongside other NIM certificates.