-snip-
Try to get everything to the latest version, then retry.
The problem was with my PGP keys.
They were very old, from 2013. I deleted the old ones and created two new keys, and I was able to verify Thomas Voegtlin's public key.
That checks out.
It's "
rare" since it's mostly caused by keys with the old SHA1 digest which shouldn't occur nowadays.
This is why I instructed to update or look for updated keys, turns out, it's you keys that's old.