On Mon, 27 Jul 2026 21:44, Robert J. Hansen said:
> -----
> sig:?::1:9710B89BCA57AD7C:1104308002:1105517602:::[User ID not
> found]:10x:::::2:

You should use --checks-igs instead of --list-sig to actually check the
signatures.  You may try

  --list-options show-unusable-sigs

to also include signature which are not shown due to their use of SHA-1.

From 2.2.18:

  * gpg: Prepare against chosen-prefix SHA-1 collisions in key
    signatures.  This change removes all SHA-1 based key signature
    from the web-of-trust.  Note that this includes all key signature
    created with dsa1024 keys.  (Version 2.2.18 limits this to key
    signatures newer than 2019-01-19.)  The new option
    --allow-weak-key-signatues can be used to override the new and
    safer behaviour.  [#4755,CVE-2019-14855]



Shalom-Salam,

   Werner

-- 
The pioneers of a warless world are the youth that
refuse military service.             - A. Einstein

Attachment: openpgp-digital-signature.asc
Description: PGP signature

_______________________________________________
Gnupg-users mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-users

Reply via email to