Also look up keys by KeyID in findSigner()
Depending on the signature's validity, fingerprint() may actually be a keyid.