Many more sigs show when I add --with-colons to --list-sigs

Walt Mankowski waltman at pobox.com
Wed Jul 29 17:49:38 CEST 2026


On Wed, Jul 29, 2026 at 10:47:09AM -0400, Robert J. Hansen via Gnupg-users wrote:
> > Thanks. I guess this helps explain why some of the signatures listed
> > by --check-sigs as usable were dsa1024, while others were unusable. My
> > dsa1024 signature is listed as usable on other people's keys, so I
> > guess that means my key doesn't use SHA-1?
> 
> Your certificate doesn't have a single RIPEMD160 signature on it.
> 
> Let's look at the machine-readable signature line:
> 
> sig:?::17:DBC3EBFC33E3FE56:995424332::::[User ID not found]:10x:::::2:
> 
> That next-to-final field, the '2', represents the hash algorithm used in
> the signature. 2 corresponds to SHA-1. RIPEMD160 corresponds to 3.
> 
> You don't have a single signature line with a 3 in that field.

I've got some 10's later on with my self-signatures for my newer
rsa4096 keys.

Maybe I'm confused by the output of --check-sigs. Since most of the
keys have a "!" and a few have "%", and since % represents a
non-supported algorithm, I was thinking that the % rows must have been
the SHA-1 sigs and the ! rows were OK.

If in fact the vast majority of signatures on my key are invalid
because of SHA-1, and most of my signatures are also invalid, I'm
wondering if it might make sense to start fresh with a new key that
doesn't have all that potentially confusing old baggage.

Walt
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://lists.gnupg.org/pipermail/gnupg-users/attachments/20260729/68d2c666/attachment.sig>


More information about the Gnupg-users mailing list