Many more sigs show when I add --with-colons to --list-sigs

Walt Mankowski waltman at pobox.com
Thu Jul 30 02:59:04 CEST 2026


On Wed, Jul 29, 2026 at 12:44:26PM -0400, Robert J. Hansen via Gnupg-users wrote:
> > I've got some 10's later on with my self-signatures for my newer
> > rsa4096 keys.
> 
> Unless you're looking to write a GnuPG output parser, I suggest not even
> looking at the machine-readable output. There's nothing useful to you there.

Except for proof that the signatures were in fact made with SHA-1.
Look, I'm just trying to understand what's going on. It's not exactly
straightforward.

> The best time to migrate away from DSA keys was in the year 2000, when
> the RSA patent was relinquished. The second best time is now.
> 
> Seriously: I don't mean to be a jerk, but you're 26 years late to the party.

Seriously, I don't mean to be a jerk either, but this also means that
gpg has had 26 years to make the output be more consistent and easier
to understand. Why do --list-sigs and --check-sigs show different
signatures? Why is --check-sigs saying that some of my signatures are
usable if they were made with SHA-1? What does "usable" even mean in
this context?
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://lists.gnupg.org/pipermail/gnupg-users/attachments/20260729/fc5ad1ca/attachment.sig>


More information about the Gnupg-users mailing list