The page https://help.riseup.net/en/security/message-security/openpgp/best-practices#self-signatures-must-not-use-sha1
explains how to check for deprecated md5 or sha1 signatures:and recommends "to regenerate a key". I do not understand what the authors mean (recreate, i.e. generate a new key?, or add a new self-signature??) and think the present formulation is or can be misleading, because for example the GnuPG Handbook https://www.gnupg.org/gph/en/manual.html is silent about how to "regenerate a key". Can anyone explain what exactly is meant and perhaps improve the text on the riseup page in the sections regarding the md5 and sha1 self-signatures ? |
_______________________________________________ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users