Why not do a detached signature using e.g. gpg -sb --output file.sig
file? Then, someone can run gpg --verify file.sig file to ensure that
the signature is valid.

(a) because the OP specifically said he was looking for integrated signatures, and

(b) detached signatures have a way of getting lost, not distributed with the executables, and so on.

Attachment: OpenPGP_signature
Description: OpenPGP digital signature

Gnupg-users mailing list

Reply via email to