Many more sigs show when I add --with-colons to --list-sigs

Walt Mankowski waltman at pobox.com
Tue Jul 28 19:12:00 CEST 2026


On Tue, Jul 28, 2026 at 05:45:48PM +0200, Werner Koch via Gnupg-users wrote:
> You should use --checks-igs instead of --list-sig to actually check the
> signatures.  You may try
> 
>   --list-options show-unusable-sigs
> 
> to also include signature which are not shown due to their use of SHA-1.

gpg --check-sigs --list-options show-unusable-sigs waltman
pub   dsa1024 1999-10-20 [SC]
      77D4D81DC47D68FA9E9E6A7C5DF19E2B67A7B584
uid           [ultimate] Walter C. Mankowski <waltman at pobox.com>
sig!3        5DF19E2B67A7B584 2001-07-05  [self-signature]
sig!3        5DF19E2B67A7B584 2004-02-09  [self-signature]
gpg: Note: third-party key signatures using the SHA1 algorithm are rejected
gpg: (use option "--allow-weak-key-signatures" to override)
sig%2        0393622EE1021E7E 2004-06-22  [Invalid digest algorithm]
sig!3        16BF8C4C0D1DAE4B 2003-01-10  Jeff Abrahamson (PhD student at Drexel University, roughly 2002 - 2007.) <jeffa at cs.drexel.edu>
sig%         1ADE8C07B1B29E59 2009-07-16  [Invalid digest algorithm]
sig!         3FEFE6DA8501AFEA 2003-01-09  LeRoy D. Cressy (ldc) <leroy at lrcressy.com>
sig!3        49820C1CEA59038E 2002-11-07  Stephen Gran <sgran at debian.org>
sig!         63DEA2E21E4CD1E8 2001-11-21  Eric J. Roode <sdn at comcast.net>
sig!3        C7C4DA125477A8C3 2004-03-08  Jon Moore <jonm at isc.upenn.edu>
sig!         D106E9E1B3D9BDEB 2008-01-04  Michael Greb <michael at thegrebs.com>
sig!         DAC1A9BD742B67FE 2002-04-19  Eric Allan Lucas <eric at lucii.org>
sig!         F5E85A700CF9091A 2001-08-08  gabriel rosenkoetter <gr at eclipsed.net>
uid           [ultimate] Walter C. Mankowski <waltman at mawode.com>
sig!3        5DF19E2B67A7B584 2005-01-29  [self-signature]
sig%         1ADE8C07B1B29E59 2009-07-16  [Invalid digest algorithm]
sig!3        3FEFE6DA8501AFEA 2005-02-06  LeRoy D. Cressy (ldc) <leroy at lrcressy.com>
sig!         D106E9E1B3D9BDEB 2008-01-04  Michael Greb <michael at thegrebs.com>
uid           [ultimate] Walter C. Mankowski <waltman at fastmail.com>
sig!3        5DF19E2B67A7B584 2025-06-20  [self-signature]
sub   elg1024 1999-10-20 [E]
sig!         5DF19E2B67A7B584 1999-10-20  [self-signature]
sub   rsa4096 2025-06-20 [S]
sig!         5DF19E2B67A7B584 2025-06-20  [self-signature]

gpg: 16 good signatures
gpg: 99 signatures not checked due to missing keys
gpg: 3 signatures not checked due to errors

Thanks, this explains what's going on. First, I need to use
--check-sigs instead of --list-sigs. Those signatures listed as valid
are all old dsa1024 sigs, but they appear to still be valid.

The second issue is that I'm missing most of my signatures. That makes
sense. My keychain was getting unweildy so I'd decided when I moved to
a new box that I'd download keys as I needed them.

Walt
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 870 bytes
Desc: not available
URL: <https://lists.gnupg.org/pipermail/gnupg-users/attachments/20260728/f0768a59/attachment-0001.sig>


More information about the Gnupg-users mailing list