Many more sigs show when I add --with-colons to --list-sigs
Walt Mankowski
waltman at pobox.com
Wed Jul 29 17:49:38 CEST 2026
On Wed, Jul 29, 2026 at 10:47:09AM -0400, Robert J. Hansen via Gnupg-users wrote:
> > Thanks. I guess this helps explain why some of the signatures listed
> > by --check-sigs as usable were dsa1024, while others were unusable. My
> > dsa1024 signature is listed as usable on other people's keys, so I
> > guess that means my key doesn't use SHA-1?
>
> Your certificate doesn't have a single RIPEMD160 signature on it.
>
> Let's look at the machine-readable signature line:
>
> sig:?::17:DBC3EBFC33E3FE56:995424332::::[User ID not found]:10x:::::2:
>
> That next-to-final field, the '2', represents the hash algorithm used in
> the signature. 2 corresponds to SHA-1. RIPEMD160 corresponds to 3.
>
> You don't have a single signature line with a 3 in that field.
I've got some 10's later on with my self-signatures for my newer
rsa4096 keys.
Maybe I'm confused by the output of --check-sigs. Since most of the
keys have a "!" and a few have "%", and since % represents a
non-supported algorithm, I was thinking that the % rows must have been
the SHA-1 sigs and the ! rows were OK.
If in fact the vast majority of signatures on my key are invalid
because of SHA-1, and most of my signatures are also invalid, I'm
wondering if it might make sense to start fresh with a new key that
doesn't have all that potentially confusing old baggage.
Walt
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://lists.gnupg.org/pipermail/gnupg-users/attachments/20260729/68d2c666/attachment.sig>
More information about the Gnupg-users
mailing list