Skip to content

New added PGP key is unverified

Summary

When I add my PGP key that was created with GnuPG version 2.2.0 on Arch Linux with a length from 4096 it says the key is "Unverified". Every commit that I sign is also "Unverified".

Steps to reproduce

  • gpg --full-gen-key
  • RSA and RSA
  • Key length: 4096
  • Finish key creation
  • Upload public key to gitlab

What is the expected correct behavior?

The new uploaded key should be "Verified"

Relevant logs and/or screenshots

gpg_unverified

Results of GitLab environment info

GitLab Community Edition 9.5.3 789cc678