Re: Signing/encryption again again...
Thomas Olsen <[email protected]>
| Newsgroups | gmane.comp.kde.users.pim |
|---|---|
| Message-ID | <[email protected]> |
On Thursday 17 June 2010 09:21:20 Brad Rogers wrote: > On Thu, 17 Jun 2010 08:48:28 +0200 > Thomas Olsen <[email protected]> wrote: > > Hello Thomas, > > > but I still wonder why other signed messages shows up as "The > > signature is valid, but the key's validity is unknown". > > Because you haven't signed the key. However, it's bad practice to sign > keys you don't know the value of. The key signing methodology involves > verifying the key you wish to sign actually belongs to the person it > purports to come from. The only sure fire way to do that is to meet > them. Signing and attributing trust values to keys of ppl you don't know > is hazardous to all concerned. > > So, if you're planning on signing keys of people you don't know, *don't*. Aha. Thanks for a very understandable explanation on a IMHO complex subject. -- Best Regards / Med venlig hilsen Thomas Olsen _______________________________________________ KDE PIM users mailing list [email protected] https://mail.kde.org/mailman/listinfo/kdepim-users
signature.asc
(application/pgp-signature, 230 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iF4EABEIAAYFAkwZ9vsACgkQge+YkdGJAWhZoAD/ZfYC6lDskufqO7kmFcXTsZYS sM9hvu4wT8Lr3q4VA18BAJmdtDKUuHQuezWmfZAXGf3PBrOpZjPe2nbwRBvj/6T/ =XxCj -----END PGP SIGNATURE-----