Re: Many more sigs show when I add --with-colons to --list-sigs

"Robert J. Hansen via Gnupg-users" <[email protected]> Wed, 29 Jul 2026 09:36:18 -0400
Newsgroups gmane.comp.encryption.gpg.user
Message-ID <[email protected]>
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============6932575619365651990==
Content-Language: en-US
Content-Type: multipart/signed; micalg=pgp-sha256;
 protocol="application/pgp-signature";
 boundary="------------3IQNoUWWhAnQHuJFN8ouv7Rl"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--------------3IQNoUWWhAnQHuJFN8ouv7Rl
Content-Type: multipart/mixed; boundary="------------HamFUSMa2SKoSMzgH9BhqZni";
 protected-headers="v1"; hp="clear"
Message-ID: <[email protected]>
Date: Wed, 29 Jul 2026 09:36:18 -0400
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Subject: Re: Many more sigs show when I add --with-colons to --list-sigs
To: [email protected]
References: <[email protected]>
 <[email protected]>
 <[email protected]> <[email protected]>
 <[email protected]> <[email protected]>
 <[email protected]>
Content-Language: en-US
From: "Robert J. Hansen" <[email protected]>
In-Reply-To: <[email protected]>

--------------HamFUSMa2SKoSMzgH9BhqZni
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

I should also say --

> DSA involves doing some complicated math on a 160-bit value. There's no=

> hard requirement the value be generated by SHA-1, and GnuPG/PGP 5+
> provides RIPEMD160 as an alternative, but in reality hardly anyone uses=

> RIPEMD160.
>=20
> This should not be confused with DSS, the Digital Signature *Standard*,=

> which specifies DSA with SHA-1 (and only SHA-1).
(This is the longer answer I alluded to in the preceding message)

DSA has been around for more than thirty years and in those decades has
undergone several rounds of change. The answer I gave there, while
correct, is only correct for *one specific early version* of DSA -- the
version GnuPG and PGP implemented at the time you first created your DSA
certificate.

The final version of DSA that used the conventional discrete logarithm
problem as a basis for security allowed up to 3072-bit keys using
256-bit hashes. However, this has since been declared obsolete by FIPS,
and the latest versions of the standard use DSA defined on an Edwards
curve, I believe.


--------------HamFUSMa2SKoSMzgH9BhqZni--

--------------3IQNoUWWhAnQHuJFN8ouv7Rl
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature.asc"

-----BEGIN PGP SIGNATURE-----

wsF5BAABCAAjFiEEFeIqXiZeEhmI9P9Fj4rGoOnxJ+8FAmpqAdIFAwAAAAAACgkQj4rGoOnxJ+/W
/BAAgueksmscgDv5msBxaEiC8+iBpAG+vyTPPRHGUhakrlM17zfPM/vp+V5LTQmXMWd9dAs4TgIY
IkCpxnZ5ECUD3ZRSOrZAYyAuEXRm7dfEmung5LDOesVEoEoXm2QAtaCCOca9Z2cfnoBz1Mcal549
ZZVQpd+09L9SGGLkAaEFXBo+Nt0DFquoEBm8y0vu+eMP20SuntdOkG9Ulv7rjoPxSZ5BDjKQnusm
VAfumm2eVfH42aJ/hwvGdrqRwbKi++N4fa5w3dbym06m0fSwq9J6KlBWzs3PDReW6Q1FNUFax90t
MBuxOUHPF1VihVdR6mr8si8kWvZ4NhRaJkFL3mCJI7Gh0UfN7RGxObnSoyVitO9qvveK3vKkX/ph
k2H5s9K793VQ7oYbJH+AcQq28woJs95hOsgtCav+XKGGqtHZEe+3zUvkAFHvl4fNtSQw+exDzljF
I2stk/mD9wKjeQmBPlsLN8u/lX7omdNEKDpAVCXh5thyY79Bi56WFLJ98d8qzTRAuuDyvOW6GavO
CGqZinhQUcVDenMrsBd9AUSG9XavUu+/1t8sx2grbax5qzNlSmyiokedAmJinlGFUbxVnmP7hmA4
E58QDckYGIayh0oAdV42gaNLqrkB1+DRNCO9Phvl54oOfWyTYVJRPogbEVDDPwxL2ZavLd49RX6e
9ME=
=ybbz
-----END PGP SIGNATURE-----

--------------3IQNoUWWhAnQHuJFN8ouv7Rl--


--===============6932575619365651990==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Gnupg-users mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-users

--===============6932575619365651990==--