Re: Signing/encryption again again...

Thomas Olsen <[email protected]>
Newsgroups gmane.comp.kde.users.pim
Message-ID <[email protected]>
On Thursday 17 June 2010 09:21:20 Brad Rogers wrote:
> On Thu, 17 Jun 2010 08:48:28 +0200
> Thomas Olsen <[email protected]> wrote:
> 
> Hello Thomas,
> 
> > but I still wonder why other signed messages shows up as "The
> > signature is valid, but the key's validity is unknown".
> 
> Because you haven't signed the key.  However, it's bad practice to sign
> keys you don't know the value of.  The key signing methodology involves
> verifying the key you wish to sign actually belongs to the person it
> purports to come from.  The only sure fire way to do that is to meet
> them.  Signing and attributing trust values to keys of ppl you don't know
> is hazardous to all concerned.
> 
> So, if you're planning on signing keys of people you don't know, *don't*.

Aha. Thanks for a very understandable explanation on a IMHO complex subject.

-- 
Best Regards / Med venlig hilsen

Thomas Olsen

_______________________________________________
KDE PIM users mailing list
[email protected]
https://mail.kde.org/mailman/listinfo/kdepim-users
signature.asc (application/pgp-signature, 230 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iF4EABEIAAYFAkwZ9vsACgkQge+YkdGJAWhZoAD/ZfYC6lDskufqO7kmFcXTsZYS
sM9hvu4wT8Lr3q4VA18BAJmdtDKUuHQuezWmfZAXGf3PBrOpZjPe2nbwRBvj/6T/
=XxCj
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.