I saved the attachments from your email (ATT00109.dat and ATT00107.txt) and
tried to verify the signature.  This is what I got:

C:\test>gpg -v ATT00109.dat
gpg: armor header: Version: GnuPG v1.3.6-cvs (GNU/Linux)
gpg: armor header: Comment: Key available at
Detached signature.
Please enter name of data file: ATT00107.txt
gpg: Signature made 05/22/04 00:19:51  using DSA key ID 49E1CBC9
gpg: using secondary key 49E1CBC9 instead of primary key 99242560
gpg: BAD signature from "David M. Shaw <dshaw at>"
gpg: textmode signature, digest algorithm SHA1

