Occasional invalid RSA signature under repeated signing (gpg 2.3.7 / libgcrypt 1.10.1)
NIIBE Yutaka
gniibe at fsij.org
Fri Jul 10 09:20:06 CEST 2026
Hello,
Thank you for your report.
Diggory Blake wrote:
> ## What happened
>
> I signed a git commit with `git commit --amend --no-edit` (which calls
> `gpg -bsau <KEY>` under the hood), and later noticed `git verify-commit`
> reports it as `BAD signature`. The key is the right one, and every
> other commit I've signed around that time verifies fine — only this one
> is broken.
How your key was generated, I wonder. This year, we encountered
an issue (of P and Q):
https://lists.gnupg.org/pipermail/gnupg-users/2026-March/068163.html
Please check your P and Q.
--
More information about the Gnupg-devel
mailing list