Re: Signing/encryption again again...
Brad Rogers <[email protected]>
| Newsgroups | gmane.comp.kde.users.pim |
|---|---|
| Organization | Catch 22 |
| Message-ID | <[email protected]> |
On Thu, 17 Jun 2010 08:48:28 +0200 Thomas Olsen <[email protected]> wrote: Hello Thomas, > but I still wonder why other signed messages shows up as "The > signature is valid, but the key's validity is unknown". Because you haven't signed the key. However, it's bad practice to sign keys you don't know the value of. The key signing methodology involves verifying the key you wish to sign actually belongs to the person it purports to come from. The only sure fire way to do that is to meet them. Signing and attributing trust values to keys of ppl you don't know is hazardous to all concerned. So, if you're planning on signing keys of people you don't know, *don't*. -- Regards _ / ) "The blindingly obvious is / _)rad never immediately apparent" Tired of doing day jobs with no thanks for what I do Do Anything You Wanna Do - Eddie & The Hotrods _______________________________________________ KDE PIM users mailing list [email protected] https://mail.kde.org/mailman/listinfo/kdepim-users
signature.asc
(application/pgp-signature, 490 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAEBCAAGBQJMGczwAAoJEEvDbGwXTTHB/B4H/01YtJR8NhhLrUMaii6v0vVB H2SZjyya/QHJn9QtG2vQnIz5xzxA6OhUiSGqJ+Q/1q6/yUDHDNGrOChBtWMRaHrW mU6Bj/FL/QjQontgZwKkeuG7XziHDRF5/UxCwv9oaMdmUQUu0QbH6tUFA6+8LZoR vTvzu7QHGHkYKYGepwzTjhwujeDAfUnQzUfIUzvO0GTH1f2WjU2Uwuc4kpspOv5O MDSpIUbvK2Jhdx8nwZfnnB40Q+LU3atCN0BBXrTGt0J3jP0LKEno6YCVTmuOWz0y CcUb9qGtJxvetqO90E9vdTIuou6aiq9Cw6e5PlcqxYsyeFWtE5lElV+SCoHn3ag= =fwJY -----END PGP SIGNATURE-----