On Wed, Jul 29, 2026 at 12:44:26PM -0400, Robert J. Hansen via Gnupg-users 
wrote:
> > I've got some 10's later on with my self-signatures for my newer
> > rsa4096 keys.
> 
> Unless you're looking to write a GnuPG output parser, I suggest not even
> looking at the machine-readable output. There's nothing useful to you there.

Except for proof that the signatures were in fact made with SHA-1.
Look, I'm just trying to understand what's going on. It's not exactly
straightforward.

> The best time to migrate away from DSA keys was in the year 2000, when
> the RSA patent was relinquished. The second best time is now.
> 
> Seriously: I don't mean to be a jerk, but you're 26 years late to the party.

Seriously, I don't mean to be a jerk either, but this also means that
gpg has had 26 years to make the output be more consistent and easier
to understand. Why do --list-sigs and --check-sigs show different
signatures? Why is --check-sigs saying that some of my signatures are
usable if they were made with SHA-1? What does "usable" even mean in
this context?

Attachment: signature.asc
Description: PGP signature

_______________________________________________
Gnupg-users mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-users

Reply via email to