Mailing List Archive

Verifying multiple detached cleartext sig's
Let's say you have a file which needs to be signed by multiple people. One
thing to do is have each person create an individual detached cleartext
signature, and then put all of them into one signature file.

* In pgp6.5.1 if you verify such a file it will automatically verify all
of these signatures.

* However, as far as I can tell, in gpg (up through v0.9.11), only the
first signature is verified.

Perhaps this could be changed so that all signatures in a given file are
automatically verified? -Todd Brooks

---------------------------------------
Todd L. Brooks
Department of Mechanical Engineering
Yale University
9 Hillhouse Avenue
PO BOX 208286
New Haven, CT 06520-8286
(203) 432-4362 (office and voice mail)
(203) 432-4363 (acoustics lab)
(203) 432-7654 (FAX)
Re: Verifying multiple detached cleartext sig's [ In reply to ]
"Todd L. Brooks" <todd.brooks@yale.edu> writes:

> Let's say you have a file which needs to be signed by multiple people. One
> thing to do is have each person create an individual detached cleartext
> signature, and then put all of them into one signature file.
>
> * In pgp6.5.1 if you verify such a file it will automatically verify all
> of these signatures.

I have not analyzed this yet. The reason may be that PGP5 does not
use the one-pass signature packets but gpg creates a faked one in
front of the cleartext and then later may not be aware, that you have
more than one signature. Not to be fixed in 1.0.0 but I give it a bug
number.


--
Werner Koch at guug.de www.gnupg.org keyid 621CC013