Multiple signatures after import.

David Shaw dshaw at jabberwocky.com
Sat Apr 12 01:07:02 CEST 2003


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wed, Apr 09, 2003 at 06:34:08PM +0400, Yenot wrote:

> I actually have seen this. It may not be related to the original
> poster's problem, but here's a way to create a UID with multiple
> self signatures (GnuPG 1.2.1):
> 
> 1) edit one of your keys
> 2) add a new UID
> 3) add *the same* UID again (do not exit after step 2)
> 4) now exit
> 
> GnuPG will merge the two UID's, but it will not merge the two self
> signatures.
> 
> The signatures are in fact different, because their creation time
> is not identical.  PGP 8.02 always retains such signatures, but
> GnuPG considers them duplicates and [usually] merges them.

No.  GnuPG will never remove a signature if it is not byte-for-byte
identical with an existing signature.  Two signatures with two
different creation dates are not indentical and are not merged.

The behavior you cite above is a feature, not a bug.

David
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2rc1 (GNU/Linux)
Comment: http://www.jabberwocky.com/david/keys.asc

iD8DBQE+lx2Y4mZch0nhy8kRAqZBAJ9xt2mB20WWj0skV8mo7rGhAvP7PACdHL2W
/7N5MeiRAxZeDY7SNLRx8qM=
=EBRT
-----END PGP SIGNATURE-----




More information about the Gnupg-devel mailing list