List Info

Thread: strip certain signatures from a keyring




strip certain signatures from a keyring
user name
1969-12-31 18:00:00

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Is there a way to strip certain signatures from a keyring, not just one
key? Such as stripping out all instances of the PGP Global signature
from all keys on a ring?
- --

Thanks!

Lance W. Haverkamp
Lance%40TheHaverkamps.net">LanceTheHaverkamps.net
Contact & encryption info:
http://thehaverkamps.net/?Lance:Contact_Me
<&gt;< <>&lt; <>&lt;

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFGGX/ab61aSFYdXm8RAn0rAJ415jxPU/XJkgoofPtF2IQGN5iPaQCfe770
j2ngU0nnlVC8eKM&#43;YGKJMYc=
=F8bH
-----END PGP SIGNATURE-----

__._,_.___
.

__,_._,___
Re: strip certain signatures from a keyring
user name
1969-12-31 18:00:00

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Lance W. Haverkamp wrote:
&gt; Is there a way to strip certain signatures from a keyring, not just one
> key? Such as stripping out all instances of the PGP Global signature
> from all keys on a ring?

I suppose it's possible to 'Select All' then Run the 'Clean' command. :-

This could take some time based upon the size of the Keyring & the
Processing power available. It would also 'Clean' *all* expired,
revoked, etc. Sigs from the entire Keyring.

JOHN ;)
Timestamp: Sunday 08 Apr 2007, 20:10 --400 (Eastern Daylight Time)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8-svn4471: (MingW32)
Comment: Public Key at: http://tinyurl.com/8cpho
Comment: Gossamer Spider Web of Trust: http://www.gswot.org
Comment: My Homepage: http://tinyurl.com/yzhbhx

iQEcBAEBCgAGBQJGGYSLAAoJEBCGy9eAtCsP9/YH/2SNDm1j2w0GPHgyHgKOkUSt
KfNXJInZXdFECCyPFdwdh1HMNF8mP5XVsnuZm+HxB243CvtxmiUQM8MUxjDGVb1K
0aCxeq4cWdr4KyyUqVDOY9Yu3U2DunFYtgbXnsla2YI2MT8pYHa4BBYtJ7Cyq+RG
/s6y9Cf/rAE/U5HGjyOnzimt6oatMrWK7DDtt1VONmOHZkO2HJozIPH/TqkEkZPJ
gygGdZkhVsV07jIpt2+aREoXHiMOSsIMEm/HemDywSwp4VMUcqy5cCFUQf/gs75n
OLbJ3PxB8RGC41WCo55Bn6Y48x+;bVZz775ZWmYrTFPpylZFKY6Fu5fC1Lv4I+C0=
=fTLx
-----END PGP SIGNATURE-----

__._,_.___
.

__,_._,___
Re: strip certain signatures from a keyring
user name
2007-04-08 20:44:02

-----BEGIN PGP SIGNED MESSAGE-----
HASH: SHA1

LANCE W. HAVERKAMP WROTE:
&GT; IS THERE A WAY TO STRIP CERTAIN SIGNATURES FROM A KEYRING, NOT JUST ONE
> KEY? SUCH AS STRIPPING OUT ALL INSTANCES OF THE PGP GLOBAL SIGNATURE
> FROM ALL KEYS ON A RING?

YOU CAN'T SPECIFY WHICH ONES TO DELETE FOR THE ENTIRE KEYRING, BUT YOU CAN USE
THE IMPORT-CLEAN OPTION TO STRIP AT LEAST THOSE SIGNATURES. IT WILL ALSO CLEAN
OTHER SIGNATURES IF YOU DO NOT HAVE THE CORRESPONDING PUBLIC KEY ALREADY ON YOUR
KEYRING.

TRY:
CD ~/.GNUPG

GPG --DELETE-KEY 0XCA57AD7C # DELETE PGP GLOBAL DIRECTORY KEY

CP PUBRING.GPG PUBRING.IMP

GPG --IMPORT-OPTIONS IMPORT-LOCAL-SIGS IMPORT-CLEAN
--IMPORT PUBRING.IMP

RM PUBRING.IMP

DELETING THE PGP GLOBAL DIRECTORY KEY (0XCA57AD7C) PRIOR TO MAKING THE COPY AND
IMPORTING WITH IMPORT-CLEAN WILL CAUSE ALL THE KEY'S SIGNATURES TO BE REMOVED.
IF YOU LEAVE THE KEY ON YOUR KEYRING, IMPORT-CLEAN WILL CONDENSE ALL THE PGP
GLOBAL DIRECTORY SIGNATURES TO JUST THE MOST RECENT.

YOU WILL WANT TO INCLUDE THE ABOVE IMPORT-OPTIONS IN GPG.CONF AS WELL AS
SPECIFYING THOSE OPTIONS FOR KEYSERVER-OPTIONS, OTHERWISE THE NEXT TIME A KEY IS
REFRESHED IT WILL RETURN TO ITS LARGER SIZE.

RELEVANT SECTION FROM THE MAN PAGE:

--IMPORT-OPTIONS PARAMETERS
THIS IS A SPACE OR COMMA DELIMITED STRING THAT GIVES OPTIONS
FOR IMPORTING KEYS. OPTIONS CAN BE PREPENDED WITH A `NO-' TO
GIVE THE OPPOSITE MEANING. THE OPTIONS ARE:

IMPORT-LOCAL-SIGS
ALLOW IMPORTING KEY SIGNATURES MARKED AS "LOCAL".
THIS IS NOT GENERALLY USEFUL UNLESS A SHARED
KEYRING SCHEME IS BEING USED. DEFAULTS TO NO.

REPAIR-PKS-SUBKEY-BUG
DURING IMPORT, ATTEMPT TO REPAIR THE DAMAGE CAUSED
BY THE PKS KEYSERVER BUG (PRE VERSION 0.9.6) THAT
MANGLES KEYS WITH MULTIPLE SUBKEYS. NOTE THAT THIS
CANNOT COMPLETELY REPAIR THE DAMAGED KEY AS SOME
CRUCIAL DATA IS REMOVED BY THE KEYSERVER, BUT IT
DOES AT LEAST GIVE YOU BACK ONE SUBKEY. DEFAULTS
TO NO FOR REGULAR --IMPORT AND TO YES FOR KEYSERVER
--RECV-KEYS.

MERGE-ONLY
DURING IMPORT, ALLOW KEY UPDATES TO EXISTING KEYS,
BUT DO NOT ALLOW ANY NEW KEYS TO BE IMPORTED.
DEFAULTS TO NO.

IMPORT-CLEAN
AFTER IMPORT, COMPACT (REMOVE ALL SIGNATURES EXCEPT
THE SELF-SIGNATURE) ANY USER IDS FROM THE NEW KEY
THAT ARE NOT USABLE. THEN, REMOVE ANY SIGNATURES
FROM THE NEW KEY THAT ARE NOT USABLE. THIS
INCLUDES SIGNATURES THAT WERE ISSUED BY KEYS THAT
ARE NOT PRESENT ON THE KEYRING. THIS OPTION IS THE
SAME AS RUNNING THE --EDIT-KEY COMMAND "CLEAN"
AFTER IMPORT. DEFAULTS TO NO.

IMPORT-MINIMAL
IMPORT THE SMALLEST KEY POSSIBLE. THIS REMOVES ALL
SIGNATURES EXCEPT THE MOST RECENT SELF-SIGNATURE ON
EACH USER ID. THIS OPTION IS THE SAME AS RUNNING
THE --EDIT-KEY COMMAND "MINIMIZE" AFTER IMPORT.
DEFAULTS TO NO.

- --
JOHN P. CLIZBE INET: JOHN (A) MOZILLA-ENIGMAIL.ORG
YOU CAN'T SPELL FIASCO WITHOUT SCO. PGP/GPG KEYID: 0X608D2A10/0X18BB373A
"WHAT'S THE KEY TO SUCCESS?&QUOT; / "TWO WORDS: GOOD DECISIONS."
&QUOT;WHAT'S THE KEY TO GOOD DECISIONS?" / "ONE WORD: EXPERIENCE."
&QUOT;HOW DO I GET EXPERIENCE?" / "TWO WORDS: BAD DECISIONS."

"JUST HOW DO THE RESIDENTS OF HAIKU, HAWAI'I HOLD CONVERSATIONS?"
-----BEGIN PGP SIGNATURE-----
VERSION: GNUPG V1.4.8-SVN-4471-2007-04-03 (WINDOWS PIII)
COMMENT: WHEN CRYPTOGRAPHY IS OUTLAWED, B25SESBVDXRSYXDZIHDPBGWGDXNLIG
COMMENT: BE PART OF THE £33T ECHELON -- USE STRONG ENCRYPTION.
COMMENT: IT'S YOUR RIGHT - FOR THE TIME BEING.
COMMENT: USING GNUPG WITH MOZILLA - HTTP://ENIGMAIL.MOZDEV.ORG

IQCVAWUBRHMAX74FMBEYUZC6AQL1JWP/F13FKMC5LYV9S8CRDVAAYA0OKRX7DBBN
Z6MKORFQWNI+ICUMJJXUSQZGMMRNCUE21EXT8CS74ROZMYRMQUEW3W5H6GVOZJTK
VUBHKYEENCYV8MOAL6FE6EN0B/ZBUPDZJTQO6&#43;NS1RHXGLCEAP3NOB81R6H4ZYBB
3A0IHZH0WMQIPWMFAUYZML8DBKXKYI0QEBEC9SCAOOQPPODIYH9ONIJWEBPS&#43;JKM
A8KFAKCPDAA7DFKSCYSHA39VBM+JAZVHVG==
=GCEO
-----END PGP SIGNATURE-----

__._,_.___
.

__,_._,___
[1-3]

about | contact  Other archives ( Real Estate discussion Medical topics )