summaryrefslogtreecommitdiffstats
path: root/doc
diff options
context:
space:
mode:
authorWerner Koch <wk@gnupg.org>2023-01-20 11:02:02 +0100
committerWerner Koch <wk@gnupg.org>2023-01-20 11:03:40 +0100
commitd98bf02a036321c8450cc836dea39671da5cfa83 (patch)
treec35eddad9c21b8b28148a7716c0b0575713fa54a /doc
parentgpg: Do not require --status-fd along with --require-compliance. (diff)
downloadgnupg2-d98bf02a036321c8450cc836dea39671da5cfa83.tar.xz
gnupg2-d98bf02a036321c8450cc836dea39671da5cfa83.zip
gpg: Replace --override-compliance-check by a real fix.
* common/compliance.c (gnupg_pk_is_allowed): Handle EdDSA. * g10/gpg.c (oOverrideComplianceCheck): Remove. (opts): Turn --override-compliance-check into a dummy option. * g10/options.h (opt): Remove override_compliance_check. * g10/sig-check.c (check_key_verify_compliance): Remove use of that option. -- The introduction of --override-compliance-check actually hid the real cause for the signature verification problem in de-vs mode for the Ed25519 key. The real fix is to handle the EdDSA algorithm in gnupg_pk_is_allowed. Fixes-commit: fb26e144adfd93051501d58f5d0d4f8826ddf436 GnuPG-bug-id: 5655
Diffstat (limited to 'doc')
-rw-r--r--doc/gpg.texi8
1 files changed, 1 insertions, 7 deletions
diff --git a/doc/gpg.texi b/doc/gpg.texi
index 792ca9aa5..47aa0a4d0 100644
--- a/doc/gpg.texi
+++ b/doc/gpg.texi
@@ -3559,13 +3559,7 @@ signatures made using SHA-1, those key signatures are considered
invalid. This options allows to override this restriction.
@item --override-compliance-check
-@opindex --override-compliance-check
-The signature verification only allows the use of keys suitable in the
-current compliance mode. If the compliance mode has been forced by a
-global option, there might be no way to check certain signature. This
-option allows to override this and prints an extra warning in such a
-case. This option is ignored in --batch mode so that no accidental
-unattended verification may happen.
+This was a temporary introduced option and has no more effect.
@item --no-default-keyring
@opindex no-default-keyring