Many more sigs show when I add --with-colons to --list-sigs

Werner Koch wk at gnupg.org
Tue Jul 28 17:45:48 CEST 2026


On Mon, 27 Jul 2026 21:44, Robert J. Hansen said:
> -----
> sig:?::1:9710B89BCA57AD7C:1104308002:1105517602:::[User ID not
> found]:10x:::::2:

You should use --checks-igs instead of --list-sig to actually check the
signatures.  You may try

  --list-options show-unusable-sigs

to also include signature which are not shown due to their use of SHA-1.

From 2.2.18:

  * gpg: Prepare against chosen-prefix SHA-1 collisions in key
    signatures.  This change removes all SHA-1 based key signature
    from the web-of-trust.  Note that this includes all key signature
    created with dsa1024 keys.  (Version 2.2.18 limits this to key
    signatures newer than 2019-01-19.)  The new option
    --allow-weak-key-signatues can be used to override the new and
    safer behaviour.  [#4755,CVE-2019-14855]



Shalom-Salam,

   Werner

-- 
The pioneers of a warless world are the youth that
refuse military service.             - A. Einstein
-------------- next part --------------
A non-text attachment was scrubbed...
Name: openpgp-digital-signature.asc
Type: application/pgp-signature
Size: 284 bytes
Desc: not available
URL: <https://lists.gnupg.org/pipermail/gnupg-users/attachments/20260728/46613db1/attachment.sig>


More information about the Gnupg-users mailing list