Many more sigs show when I add --with-colons to --list-sigs
Robert J. Hansen
rjh at sixdemonbag.org
Wed Jul 29 15:36:18 CEST 2026
I should also say --
> DSA involves doing some complicated math on a 160-bit value. There's no
> hard requirement the value be generated by SHA-1, and GnuPG/PGP 5+
> provides RIPEMD160 as an alternative, but in reality hardly anyone uses
> RIPEMD160.
>
> This should not be confused with DSS, the Digital Signature *Standard*,
> which specifies DSA with SHA-1 (and only SHA-1).
(This is the longer answer I alluded to in the preceding message)
DSA has been around for more than thirty years and in those decades has
undergone several rounds of change. The answer I gave there, while
correct, is only correct for *one specific early version* of DSA -- the
version GnuPG and PGP implemented at the time you first created your DSA
certificate.
The final version of DSA that used the conventional discrete logarithm
problem as a basis for security allowed up to 3072-bit keys using
256-bit hashes. However, this has since been declared obsolete by FIPS,
and the latest versions of the standard use DSA defined on an Edwards
curve, I believe.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <https://lists.gnupg.org/pipermail/gnupg-users/attachments/20260729/00b9fe35/attachment.sig>
More information about the Gnupg-users
mailing list