Re: Many more sigs show when I add --with-colons to --list-sigs
"Robert J. Hansen via Gnupg-users" <[email protected]> Wed, 29 Jul 2026 22:36:53 -0400
| Newsgroups | gmane.comp.encryption.gpg.user |
|---|---|
| Message-ID | <[email protected]> |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============5581370641030978934== Content-Language: en-US Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="------------m4okfmKXZFPKtHyQDEWDYhSz" This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------m4okfmKXZFPKtHyQDEWDYhSz Content-Type: multipart/mixed; boundary="------------SkDZnrLM9OPnF5oRvkPdPEl4"; protected-headers="v1"; hp="clear" Message-ID: <[email protected]> Date: Wed, 29 Jul 2026 22:36:53 -0400 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: Many more sigs show when I add --with-colons to --list-sigs To: [email protected] References: <[email protected]> <[email protected]> <[email protected]> <[email protected]> <[email protected]> <[email protected]> <[email protected]> <[email protected]> <[email protected]> <[email protected]> <[email protected]> Content-Language: en-US From: "Robert J. Hansen" <[email protected]> In-Reply-To: <[email protected]> --------------SkDZnrLM9OPnF5oRvkPdPEl4 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable > Except for proof that the signatures were in fact made with SHA-1. Look= , > I'm just trying to understand what's going on. It's not exactly=20 > straightforward. This is sort of like a LibreOffice user asking detailed questions about why their word processor document is structured the way it is. There are answers, but the answers are highly technical and not really relevant to how you use GnuPG. It's reasonable to ask, "do you really need to go down this rabbit hole?" If you do, then I'm happy to explain GnuPG data structures and internals. But if you don't, I'd like to devote my limited free time to other pursuits. :) > Why do --list-sigs and --check-sigs show different signatures? I'm afraid this answer will seem condescending: I don't mean it to be. This answer is accurate. Different commands show different outputs because they do different thing= s. To list a signature, the only thing GnuPG needs is the signature. If you give me a document with 100 signatures and I ask it to list the signatures, I'll get a hundred signatures back. To check a signature, GnuPG needs the document, the signature, and the public part of the certificate used for signing. If you give me a document with 100 signatures and I only have the public cert for one, GnuPG will report *one* signature check and say "99 signatures went unchecked for lack of a public cert." Different commands show different outputs because they do different thing= s. > Seriously, I don't mean to be a jerk either, but this also means that > gpg has had 26 years to make the output be more consistent and easier > to understand. Yep. If you're saying GnuPG could use some work, everyone here is in agreement. Take a look at our bug tracker sometime. If you know C and cryptographic engineering, things will get better faster if you help. (Also, for the record, I'm not part of the GnuPG development team. I'm just a user. I'm speaking only as a member of the community, not as part of the team.) --------------SkDZnrLM9OPnF5oRvkPdPEl4-- --------------m4okfmKXZFPKtHyQDEWDYhSz Content-Type: application/pgp-signature; name="OpenPGP_signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="OpenPGP_signature.asc" -----BEGIN PGP SIGNATURE----- wsF5BAABCAAjFiEEFeIqXiZeEhmI9P9Fj4rGoOnxJ+8FAmpquMUFAwAAAAAACgkQj4rGoOnxJ+82 XQ/7Bn44ACWkJ9KhuBFPHeqEKHnmKxKz/fPBjrerKb/cQZ4XShTKmP/oOPARb10nqKTFOx4iioNa UtLV7XroYGGl3mnAmEeIL6yDH0NZYwQA6Gc5gz8foQvLFcm3d75fh9CFW1ClcOHppy3lWTd9tAdR 1RaDek8nIHehMj5WPjerjBEykp1mKkUoKN6PGojRIZAiaj70k6i131R30e1Ru+kSJwQVmyCmPCYE ehC0wB2quQaUL4/mhINUnIDZjBryl587nwhJWzygtSNCkF/IQL8g3qcHQqLVeMBJe48rg4Y29kRy vxIt8Du/yADN2f9iHoPZtKaTd3XqIGOugK5evg0xcCL56wx7p+GKsFIP3UyYMDAWGnnvi+3Xj6rd eD6vUr1OU0SH5cA3pY2kz49rVtXUiZZCTXrkZOWdtjMmlzk9YEQig2e6r3PfV4/FcL9WOFaIc4x4 UHXWE3k0cv07z3h0hluTaa8gugJOyj+K3cjZmiZLoBxRvZT+bqxxKJpFDT7Yo4Jg6fZ9mdWqW8up NgvcQDOG2V5CLNDfIcb7iP0pA7wf+ovQmus+mGAjkTlZx1E4yntzf7PBM1ptUFDaFAsyAQWYsB4L aMmWZqz4YRtNGr3V9AvdO4L4d538Yww1iTK3x4USyzIUkT/y0YubziF3nKMrDcxgs03WFS2zUpyM rHI= =5Ejr -----END PGP SIGNATURE----- --------------m4okfmKXZFPKtHyQDEWDYhSz-- --===============5581370641030978934== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Gnupg-users mailing list [email protected] https://lists.gnupg.org/mailman/listinfo/gnupg-users --===============5581370641030978934==--