On Mon, 27 Jul 2026 21:44, Robert J. Hansen said: > ----- > sig:?::1:9710B89BCA57AD7C:1104308002:1105517602:::[User ID not > found]:10x:::::2:
You should use --checks-igs instead of --list-sig to actually check the
signatures. You may try
--list-options show-unusable-sigs
to also include signature which are not shown due to their use of SHA-1.
From 2.2.18:
* gpg: Prepare against chosen-prefix SHA-1 collisions in key
signatures. This change removes all SHA-1 based key signature
from the web-of-trust. Note that this includes all key signature
created with dsa1024 keys. (Version 2.2.18 limits this to key
signatures newer than 2019-01-19.) The new option
--allow-weak-key-signatues can be used to override the new and
safer behaviour. [#4755,CVE-2019-14855]
Shalom-Salam,
Werner
--
The pioneers of a warless world are the youth that
refuse military service. - A. Einstein
openpgp-digital-signature.asc
Description: PGP signature
_______________________________________________ Gnupg-users mailing list [email protected] https://lists.gnupg.org/mailman/listinfo/gnupg-users
