On Sun, Sep 09, 2018 at 22:43:35 +0200, Ludovic Courtès wrote: > A significant difference compared to ‘gpg --verify’ is that it doesn’t > check whether keys are expired or revoked; all that matters is whether > the signature is valid and whether the signing key is in the specified > keyring. I think that’s what we want when checking the signature of a > tarball or Git commit. Agreed. Git's use of `gpg --verify' is particularly annoying for this. > Unfortunately the keybox format and tools are poorly documented, which > is why I gave examples on how to do that in guix.texi. Thank you! > Feedback welcome! LGTM. Thanks for CC'ing. -- Mike Gerwitz Free Software Hacker+Activist | GNU Maintainer & Volunteer GPG: D6E9 B930 028A 6C38 F43B 2388 FEF6 3574 5E6F 6D05 https://mikegerwitz.com