You can easily use GPG to symmetrically encrypt a file having a passphrase (gpg -c). If the passphrase has enough entropy, you do not need to have an extra step of generating a secret essential. What does "enough entropy" wholesale magnets mean? Your encryption needs to withstand offline attacks, exactly where the attacker can make cracking attempts as fast as his hardware permits it. Having a tiny Computer farm, the attacker may be able to make a couple hundred billion attempts per second, which is roughly 2^69 per wholesale rare earth magnets for sale magnets decade. So with an entropy of 2^70 you are going to be protected. That suggests in case your passphrase consists of totally random letters (reduced or upper case) and digits, it ought to be 12 characters extended.
Now to store that passphrase, you may use GPG with its usual crucial pairs. Use gpg --gen-key to generate a important pair, and gpg -e to encrypt the passphrase used to encrypt the big file for one or alot more essential pairs.
Here's a sketch on how you can do the encryption (note that I prevent placing the passphrase around the command line or in industrial magnets suppliers the atmosphere, so as to make confident a different user can not discover it by taking a look at the ps output while the command is operating
