Signature fields can be one of the eight possible values.
-
Signed -
Unsigned -
Bad Signature -
Invalid Signature -
Expired -
Invalid Chain -
Untrusted Root -
Explicit Distrust
Values with whitespace must be enclosed in quotes.
For example:
digsig_result:Signed or digsig_result:"Invalid Chain"