On Tue,  4 Sep 2018 10:08, roman.fied...@ait.ac.at said:


The signature is corrupted in that it has a packet which is expected
only in a key.  Or the provided key has a data signature packet etc.

How did you create the keyfile and the signature?

> Could it be, that "--throw-keyids" at signature creation to then avoid
> XKeyscore-traffic-analysis [1] is not compatible with signature
> verification? 

No.  The keyid (or the fingerprint in newer version) is mandatory for a
signature packet.  Leaving this out would not help because it is easy to
figure out the key by trial verification against all known keys.  And
traffic analysis can be done without crypto operations.



Die Gedanken sind frei.  Ausnahmen regelt ein Bundesgesetz.

Attachment: pgpMT7zdIS9uc.pgp
Description: PGP signature

Gnupg-users mailing list

Reply via email to