Re: Signing/encryption again again...

Brad Rogers <[email protected]>
Newsgroups gmane.comp.kde.users.pim
Organization Catch 22
Message-ID <[email protected]>
On Thu, 17 Jun 2010 08:48:28 +0200
Thomas Olsen <[email protected]> wrote:

Hello Thomas,

> but I still wonder why other signed messages shows up as "The
> signature is valid, but the key's validity is unknown".

Because you haven't signed the key.  However, it's bad practice to sign
keys you don't know the value of.  The key signing methodology involves
verifying the key you wish to sign actually belongs to the person it
purports to come from.  The only sure fire way to do that is to meet
them.  Signing and attributing trust values to keys of ppl you don't know
is hazardous to all concerned.

So, if you're planning on signing keys of people you don't know, *don't*.

-- 
 Regards  _
         / )           "The blindingly obvious is
        / _)rad        never immediately apparent"
Tired of doing day jobs with no thanks for what I do
Do Anything You Wanna Do - Eddie & The Hotrods

_______________________________________________
KDE PIM users mailing list
[email protected]
https://mail.kde.org/mailman/listinfo/kdepim-users
signature.asc (application/pgp-signature, 490 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQEcBAEBCAAGBQJMGczwAAoJEEvDbGwXTTHB/B4H/01YtJR8NhhLrUMaii6v0vVB
H2SZjyya/QHJn9QtG2vQnIz5xzxA6OhUiSGqJ+Q/1q6/yUDHDNGrOChBtWMRaHrW
mU6Bj/FL/QjQontgZwKkeuG7XziHDRF5/UxCwv9oaMdmUQUu0QbH6tUFA6+8LZoR
vTvzu7QHGHkYKYGepwzTjhwujeDAfUnQzUfIUzvO0GTH1f2WjU2Uwuc4kpspOv5O
MDSpIUbvK2Jhdx8nwZfnnB40Q+LU3atCN0BBXrTGt0J3jP0LKEno6YCVTmuOWz0y
CcUb9qGtJxvetqO90E9vdTIuou6aiq9Cw6e5PlcqxYsyeFWtE5lElV+SCoHn3ag=
=fwJY
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.