Occasional invalid RSA signature under repeated signing (gpg 2.3.7 / libgcrypt 1.10.1)

NIIBE Yutaka gniibe at fsij.org
Fri Jul 10 09:20:06 CEST 2026


Hello,

Thank you for your report.

Diggory Blake wrote:
> ## What happened
>
> I signed a git commit with `git commit --amend --no-edit` (which calls
> `gpg -bsau <KEY>` under the hood), and later noticed `git verify-commit`
> reports it as `BAD signature`. The key is the right one, and every
> other commit I've signed around that time verifies fine — only this one
> is broken.

How your key was generated, I wonder.  This year, we encountered
an issue (of P and Q):

    https://lists.gnupg.org/pipermail/gnupg-users/2026-March/068163.html

Please check your P and Q.
-- 



More information about the Gnupg-devel mailing list