Encrypt and Decrypt Files with PGP
Configuration → Settings → Certificates
Use PGP keys to protect CSV files in transit: decrypt files sent to NIM, or encrypt and sign files NIM sends to a trusted recipient.
PGP encryption uses a public/private key pair. NIM stores the keys in its certificate repository. The important rule is simple: public keys can be shared; private keys must stay with their owner.
Never send a private PGP key through email, HTTP, unsecured FTP, tickets, or shared file locations. Store and exchange it only through your organization’s approved secure process.
Choose the workflowDirect link to Choose the workflow
| What you need to do | Key NIM needs | Key to share | Where to configure it |
|---|---|---|---|
| Decrypt an encrypted CSV file sent to NIM | NIM’s private key | NIM’s matching public key goes to the sending party | CSV-File or CSV-File-SFTP connector |
| Encrypt a CSV file NIM sends out | Recipient’s public key | The recipient keeps their private key | Export task or multi-export task |
| Sign a CSV file NIM sends out | NIM’s private key | NIM’s matching public key goes to the recipient | Export or multi-export task |
Generate a key pair for NIMDirect link to Generate a key pair for NIM
Generate a NIM-owned key pair when another party needs to encrypt files that NIM will decrypt, or when NIM needs to sign outgoing files.
-
Go to Configuration → Settings → Certificates.
-
Select Generate PGP key.
-
Complete the key details:
Field Guidance Certificate name Use a descriptive name that identifies the file exchange and owner, such as HR-Partner-Inbound-2026.Primary key algorithm Choose the algorithm required by your organization or file-exchange partner. Expiration Optionally set an expiration using a number plus y,m,w, ord; for example,3wmeans three weeks.User IDs Identify the person or organization that owns the key. Subkeys Optionally add, remove, or set expiration for subkeys according to your key-management policy.
- Select Generate. The key appears in the certificate list.
Share NIM’s public key for inbound encryptionDirect link to Share NIM’s public key for inbound encryption
When a partner must send NIM an encrypted file, export and provide them only the public portion of NIM’s key:
- Go to Configuration → Settings → Certificates.
- Find the NIM-owned PGP key.
- Select its export button to download the public key.
- Send the public key to the partner through an approved channel. They use it to encrypt the file; NIM uses its private key to decrypt the received file.
Import a recipient’s public key for outbound encryptionDirect link to Import a recipient’s public key for outbound encryption
When NIM must encrypt files before sending them to another party, obtain that party’s public PGP key.
- Verify the key’s owner and fingerprint through your organization’s approved process.
- Go to Configuration → Settings → Certificates and select Add.
- Enter a descriptive name, select the recipient’s public key file, provide a password if required, and select Add.
- Configure the selected public key in the export task or multi-export task.
- Run a controlled export and confirm the recipient can decrypt the resulting file.
Configure encrypted file exchangeDirect link to Configure encrypted file exchange
Encrypted inbound CSV filesDirect link to Encrypted inbound CSV files
Configure the CSV-File or CSV-File-SFTP connector to use the NIM-owned private PGP key. Test with a non-production encrypted file from the sender before scheduling collection.
Encrypted and signed exportsDirect link to Encrypted and signed exports
In an export or multi-export task, enable PGP file encryption and select the recipient’s public key. If the recipient must validate that NIM produced the file, also select the appropriate NIM private key for signing.
Export tasks can produce armored output (.asc) or binary output (.gpg). Agree on the expected format with the receiving party before automating transfer.
Operate PGP keys safelyDirect link to Operate PGP keys safely
- Confirm the key owner and purpose before importing a public key or sharing one of NIM’s public keys.
- Monitor expiration and rotate keys before a scheduled import or export fails.
- Test a replacement key with a controlled file before retiring the previous key.
- Remove retired keys only after every dependent connector, export task, and file-exchange partner uses the replacement.
- Use the certificate expiration notification tutorial to monitor key lifecycles alongside other NIM certificates.