Many more sigs show when I add --with-colons to --list-sigs
Walt Mankowski
waltman at pobox.com
Tue Jul 28 13:46:49 CEST 2026
On Mon, Jul 27, 2026 at 09:44:01PM -0400, Robert J. Hansen via Gnupg-users wrote:
> > I'm trying to understand some odd behavior I'm seeing in gpg. I've had
> > my key since 1999 and I've got dozens of signatures on it. But when I
> > run
>
> A partial answer:
>
> -----
> sig:?::1:9710B89BCA57AD7C:1104308002:1105517602:::[User ID not
> found]:10x:::::2:
> sig:?::1:9710B89BCA57AD7C:1105474213:1106683813:::[User ID not
> found]:10x:::::2:
> sig:?::1:9710B89BCA57AD7C:1106640560:1107850160:::[User ID not
> found]:10x:::::2:
> sig:?::1:9710B89BCA57AD7C:1107807915:1109017515:::[User ID not
> found]:10x:::::2:
> sig:?::1:9710B89BCA57AD7C:1108780465:1109990065:::[User ID not
> found]:10x:::::2:
> sig:?::1:9710B89BCA57AD7C:1110013668:1111223268:::[User ID not
> found]:10x:::::2:
> sig:?::1:9710B89BCA57AD7C:1111310073:1112519673:::[User ID not
> found]:10x:::::2:
> sig:?::1:9710B89BCA57AD7C:1112519896:1113729496:::[User ID not
> found]:10x:::::2:
> sig:?::1:9710B89BCA57AD7C:1113726620:1114936220:::[User ID not
> found]:10x:::::2:
> sig:?::1:9710B89BCA57AD7C:1113769839:1114979439:::[User ID not
> found]:10x:::::2:
> sig:?::1:9710B89BCA57AD7C:1114978523:1116188123:::[User ID not
> found]:10x:::::2:
> sig:?::1:9710B89BCA57AD7C:1116146221:1117355821:::[User ID not
> found]:10x:::::2:
> sig:?::1:9710B89BCA57AD7C:1116146221:1117355821:::[User ID not
> found]:10x:::::2:
> sig:?::1:9710B89BCA57AD7C:1116319455:1117529055:::[User ID not
> found]:10x:::::2:
> sig:?::1:9710B89BCA57AD7C:1117485606:1118695206:::[User ID not
> found]:10x:::::2:
> sig:?::1:9710B89BCA57AD7C:1117571920:1118781520:::[User ID not
> found]:10x:::::2:
> -----
>
> See all those signatures coming from the same certificate? GnuPG treats
> only the most recent signature from a certificate as being the
> definitive one. For instance, a revoked certificate will have a self
> signature and a revocation signature: the revsig is newer, so it governs.
>
> The human-friendly interface suppresses a lot of data that isn't
> relevant (such as, e.g., signatures that aren't being considered). The
> --with-colons interface is meant for machines to process and reveals a
> lot more data.
>
> This doesn't account for everything you're seeing (I don't think), but
> it does account for a lot.
Thanks, this gives me something to look into. I also can see some of
that, in an abbreviated format, by running `--list-sigs --verbose`.
One of the things I'm finding confusing is that while I've revoked
some UIDs because they're for old email addresses I no longer have
access to, I've never revoked the original key that dates back to
1999. Most of those dozens of signatures I have were from back in the
2000s when my local LUG used to have keysigning parties at our monthly
meetings.
But since that original key was dsa1024, in the past few years I've
added subkeys with stronger encryption. My latest signing key is
rsa4096. Do I need to get people to sign the new subkey as well?
Walt
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://lists.gnupg.org/pipermail/gnupg-users/attachments/20260728/7cbb391e/attachment-0001.sig>
More information about the Gnupg-users
mailing list