# Signed commits on gitea.com fail to verify

**URL:** <https://forum.gitea.com/t/signed-commits-on-gitea-com-fail-to-verify/3940>\
**Category:** Install/Maintain/Configure\
**Created:** [October 16, 2021, 7:02pm UTC](https://forum.gitea.com/t/signed-commits-on-gitea-com-fail-to-verify/3940 "2021-10-16T19:02:16Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![dachary](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/dachary/32/4990_2.png) [@dachary](https://forum.gitea.com/u/dachary)\
**Post date:** [October 16, 2021, 7:02pm UTC](https://forum.gitea.com/t/signed-commits-on-gitea-com-fail-to-verify/3940/1 "2021-10-16T19:02:16Z")

</div>

Bonjour,

This [pull request](https://gitea.com/gitea/test-env/pulls/9) shows a signed commit tagged as suspicious.

 ![image](https://us1.discourse-cdn.com/flex020/uploads/gitea/original/2X/6/6b40e4e9f63420e2d96328b0d4f060ea5cdeb017.png)

However, when I verify it manually, it checks out:

```auto
$ git verify-commit 9eee365e33
gpg: Signature made sam. 16 oct. 2021 08:50:47 -10
gpg: using RSA key E99FFE83DF73E72FB6B264ED992D23B392F9E4F2
gpg: Good signature from "Loic Dachary (OuoU) <loic@gnu.org>" [ultimate]
gpg: aka "Loic Dachary (OuoU) <loic@dachary.org>" [ultimate]
gpg: aka "Loic Dachary (OuoU) <loic@debian.org>" [ultimate]

```

and the corresponding GPG public key is set correctly in the preferences.

 ![image](https://us1.discourse-cdn.com/flex020/uploads/gitea/original/2X/2/2cf6fc8f763da7e24d3234af2cfe88ab93b48bf9.png)

Am I doing something wrong?

---

<div class="post-metadata">

**Author:** ![techknowlogick](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/techknowlogick/32/4706_2.png) [@techknowlogick](https://forum.gitea.com/u/techknowlogick)\
**Post date:** [October 17, 2021, 12:32am UTC](https://forum.gitea.com/t/signed-commits-on-gitea-com-fail-to-verify/3940/2 "2021-10-17T00:32:04Z")

</div>

I believe it is due to the “trust model” of that specific repo (as you are not a member of the org, it may see your signature as suspicious). If you look at that same commit, but under your fork it should verify as valid.

---

<div class="post-metadata">

**Author:** ![dachary](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/dachary/32/4990_2.png) [@dachary](https://forum.gitea.com/u/dachary)\
**Post date:** [October 17, 2021, 2:32am UTC](https://forum.gitea.com/t/signed-commits-on-gitea-com-fail-to-verify/3940/3 "2021-10-17T02:32:10Z")

</div>

It is also [considered to be suspicious](https://gitea.com/dachary/test-env/commits/branch/wip-doc) in my own repository 🤔

 ![image](https://us1.discourse-cdn.com/flex020/uploads/gitea/original/2X/7/747dbd405556cdf1fcea3bef98468a531df8666d.png)

---

<div class="post-metadata">

**Author:** ![dachary](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/dachary/32/4990_2.png) [@dachary](https://forum.gitea.com/u/dachary)\
**Post date:** [October 17, 2021, 2:57pm UTC](https://forum.gitea.com/t/signed-commits-on-gitea-com-fail-to-verify/3940/4 "2021-10-17T14:57:38Z")

</div>

For the record [@lunny tried](https://gitea.com/gitea/test-env/pulls/9#issuecomment-593553) to change the [Signing Verification Settings](https://gitea.com/dachary/test-env/settings) for the repository but the commit signature is still considered suspicious.

I also tried to change the setting as follows and push another signed commit but commit signature is still considered suspicious.

 ![image](https://us1.discourse-cdn.com/flex020/uploads/gitea/original/2X/1/1589748970cb2d595db33f578b3171c3adb4e5d5.png)

---

<div class="post-metadata">

**Author:** ![techknowlogick](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/techknowlogick/32/4706_2.png) [@techknowlogick](https://forum.gitea.com/u/techknowlogick)\
**Post date:** [October 17, 2021, 9:41pm UTC](https://forum.gitea.com/t/signed-commits-on-gitea-com-fail-to-verify/3940/5 "2021-10-17T21:41:00Z")

</div>

😬 that’s uhh… not good.

Let me poke around at it a bit and see what I figure out.

---

<div class="post-metadata">

**Author:** ![dachary](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/dachary/32/4990_2.png) [@dachary](https://forum.gitea.com/u/dachary)\
**Post date:** [November 29, 2021, 7:17am UTC](https://forum.gitea.com/t/signed-commits-on-gitea-com-fail-to-verify/3940/6 "2021-11-29T07:17:56Z")

</div>

The email associated with the key was not verified (thanks @zeripath for suggesting that might be the source of the problem).

 ![image](https://us1.discourse-cdn.com/flex020/uploads/gitea/original/2X/2/2d1d889c0ec55b8772bfa30de7aa90b7caa1c841.png)

After validating the email, I removed the GPG key, added it again, pushed a branch with a signed commit and it’s all good. Mystery solved 🎉

 ![image](https://us1.discourse-cdn.com/flex020/uploads/gitea/original/2X/4/44af7e7d3b95fe99c34106e27f7b54cb4546b3e9.png)

---

<div class="post-metadata">

**Author:** ![zeripath](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/zeripath/32/4745_2.png) [@zeripath](https://forum.gitea.com/u/zeripath)\
**Post date:** [November 29, 2021, 9:10am UTC](https://forum.gitea.com/t/signed-commits-on-gitea-com-fail-to-verify/3940/7 "2021-11-29T09:10:25Z")

</div>

Yeah we can’t safely verify a commit against an unvalidated/unactivated email address - otherwise someone could easily spoof identities. We need to confirm that you have the email address you’re purporting to sign for.

The slight gotcha here is that instead of storing all of the addresses that a key has we only store the ones that are activated at the time of addition meaning that if you add a key and then later activate an address you have to re-add the key or sign a token with the key (thus confirming you have the key) allowing it to match any of the activated addresses we have for you. (Likely we should just store all of the keys and match activated ones at the time of verification but I’ve not had the chance to do that.)

---

<div class="post-metadata">

**Author:** ![lmtr0](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/lmtr0/32/6875_2.png) [@lmtr0](https://forum.gitea.com/u/lmtr0)\
**Post date:** [May 12, 2025, 2:02am UTC](https://forum.gitea.com/t/signed-commits-on-gitea-com-fail-to-verify/3940/8 "2025-05-12T02:02:54Z")

</div>

So, funny enough, my problem is similar.  
I also cannot verify the signature of a commit, but only occasionally.  
Here is a photo that demonstrates the problem:

 ![image](https://us1.discourse-cdn.com/flex020/uploads/gitea/original/2X/f/f0da2cc274de9a02a06fbebd4e89b6b86b0cdc3b.png)

All the commits under git show a good signature:  
**(I can’t upload more than one pick because I’m a new user)**

So, I’m confused…

Gitea: 1.23.7  
Git client: Gitbutler  
I’ve added my gpg keys (and verified them) and verified my email:  
**(I can’t upload more than one pick because I’m a new user)**

I’ve tried all the trust models, nothing works…

---

<div class="post-metadata">

**Author:** ![lmtr0](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/lmtr0/32/6875_2.png) [@lmtr0](https://forum.gitea.com/u/lmtr0)\
**Post date:** [May 12, 2025, 2:04am UTC](https://forum.gitea.com/t/signed-commits-on-gitea-com-fail-to-verify/3940/9 "2025-05-12T02:04:32Z")

</div>

If I commit with git, it works every time, Gitbutler only every so often.

In both cases, however, git very-commit works.

---

<div class="post-metadata">

**Author:** ![lmtr0](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/lmtr0/32/6875_2.png) [@lmtr0](https://forum.gitea.com/u/lmtr0)\
**Post date:** [June 8, 2025, 4:40pm UTC](https://forum.gitea.com/t/signed-commits-on-gitea-com-fail-to-verify/3940/10 "2025-06-08T16:40:25Z")

</div>

Fixed in version 1.24

---

<div class="post-metadata">

**Author:** ![lunny](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/lunny/32/4701_2.png) [@lunny](https://forum.gitea.com/u/lunny)\
**Post date:** [June 15, 2025, 12:33am UTC](https://forum.gitea.com/t/signed-commits-on-gitea-com-fail-to-verify/3940/11 "2025-06-15T00:33:49Z")

</div>


