Re: Many more sigs show when I add --with-colons to --list-sigs
Walt Mankowski via Gnupg-users <[email protected]> Tue, 28 Jul 2026 07:46:49 -0400
| Newsgroups | gmane.comp.encryption.gpg.user |
|---|---|
| Message-ID | <[email protected]> |
--===============2707240416309185159== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="ygAoik/9oDVyBc0I" Content-Disposition: inline --ygAoik/9oDVyBc0I Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Mon, Jul 27, 2026 at 09:44:01PM -0400, Robert J. Hansen via Gnupg-users = wrote: > > I'm trying to understand some odd behavior I'm seeing in gpg. I've had > > my key since 1999 and I've got dozens of signatures on it. But when I > > run >=20 > A partial answer: >=20 > ----- > sig:?::1:9710B89BCA57AD7C:1104308002:1105517602:::[User ID not > found]:10x:::::2: > sig:?::1:9710B89BCA57AD7C:1105474213:1106683813:::[User ID not > found]:10x:::::2: > sig:?::1:9710B89BCA57AD7C:1106640560:1107850160:::[User ID not > found]:10x:::::2: > sig:?::1:9710B89BCA57AD7C:1107807915:1109017515:::[User ID not > found]:10x:::::2: > sig:?::1:9710B89BCA57AD7C:1108780465:1109990065:::[User ID not > found]:10x:::::2: > sig:?::1:9710B89BCA57AD7C:1110013668:1111223268:::[User ID not > found]:10x:::::2: > sig:?::1:9710B89BCA57AD7C:1111310073:1112519673:::[User ID not > found]:10x:::::2: > sig:?::1:9710B89BCA57AD7C:1112519896:1113729496:::[User ID not > found]:10x:::::2: > sig:?::1:9710B89BCA57AD7C:1113726620:1114936220:::[User ID not > found]:10x:::::2: > sig:?::1:9710B89BCA57AD7C:1113769839:1114979439:::[User ID not > found]:10x:::::2: > sig:?::1:9710B89BCA57AD7C:1114978523:1116188123:::[User ID not > found]:10x:::::2: > sig:?::1:9710B89BCA57AD7C:1116146221:1117355821:::[User ID not > found]:10x:::::2: > sig:?::1:9710B89BCA57AD7C:1116146221:1117355821:::[User ID not > found]:10x:::::2: > sig:?::1:9710B89BCA57AD7C:1116319455:1117529055:::[User ID not > found]:10x:::::2: > sig:?::1:9710B89BCA57AD7C:1117485606:1118695206:::[User ID not > found]:10x:::::2: > sig:?::1:9710B89BCA57AD7C:1117571920:1118781520:::[User ID not > found]:10x:::::2: > ----- >=20 > See all those signatures coming from the same certificate? GnuPG treats > only the most recent signature from a certificate as being the > definitive one. For instance, a revoked certificate will have a self > signature and a revocation signature: the revsig is newer, so it governs. >=20 > The human-friendly interface suppresses a lot of data that isn't > relevant (such as, e.g., signatures that aren't being considered). The > --with-colons interface is meant for machines to process and reveals a > lot more data. >=20 > This doesn't account for everything you're seeing (I don't think), but > it does account for a lot. Thanks, this gives me something to look into. I also can see some of that, in an abbreviated format, by running `--list-sigs --verbose`. One of the things I'm finding confusing is that while I've revoked some UIDs because they're for old email addresses I no longer have access to, I've never revoked the original key that dates back to 1999. Most of those dozens of signatures I have were from back in the 2000s when my local LUG used to have keysigning parties at our monthly meetings. But since that original key was dsa1024, in the past few years I've added subkeys with stronger encryption. My latest signing key is rsa4096. Do I need to get people to sign the new subkey as well? Walt --ygAoik/9oDVyBc0I Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEsBVFaKgbhBVkCl7wWw6znYG+qIkFAmpolqgACgkQWw6znYG+ qInM8g//RYgexyqj3gkwNbdWlcbvqk3SltKreBYYn3TgvCr+F8ERhmlsfBJA7B+a 78wbkV7phu/apT0I228IP9SFv1XMTffsYx8PSZj3BKzoy7wnl+37M/STRflp7RdY W4rGLEW5LXKXC4TSri5ODiqMI61d5Sb6Al52stnNL9plyCfVThkc0sg5J+nU860q eTCq/49XKB3VNanZtR/1yquWGCxYrnjYWG/MYvENm09f50WPVIJjFuJiWRvzPACV 0J0rN+GBTHrNcse/umV6cojPeJ1kgqLqMsetHKChFxfQEofFZyJ5p3K1yWy+XiAt 3LAPaE5wcNfX1v1OBLIGsMx/4OGjgJmzRr9J6cu+bSIJCOrU0mkmGwGDYmWiTtWI HZ+OU7gZiTOgul60V72SRwKDtLBntB7SZoX4wVQ4eGjdCiMXV3FsUMG7SAp2wXjV UoR5oZcpiqGa6FkkP3nRCS8CTUzaUyyegAJ76Mi6htD/e6gY/Ldg1Az568P8RXT6 41Y4246MnEycEOYVHvFMAZ+tTej+P7XzCYlFF6OxaR9+a2zWQmdjCFDiXrQ9/KBJ T1cSPOqCacSPxuQNR5566tbzVllDRfW00OPn9CvLj4b4veDBXWUJ9IciGJJIIKjL oUUVKO34dokKJhJNvbB8bpM0sN/M9SsfO9mw552Db3CpvWkhyZc= =4l+8 -----END PGP SIGNATURE----- --ygAoik/9oDVyBc0I-- --===============2707240416309185159== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Gnupg-users mailing list [email protected] https://lists.gnupg.org/mailman/listinfo/gnupg-users --===============2707240416309185159==--