On Sat, Aug 27, 2011 at 1:03 AM, Doug Barton <[email protected]> wrote:

> I have a particular concern that if I sign a key with "I checked
> carefully" that I really did. Moreover, I have a philosophical prejudice
> that if I *can't* say "I checked carefully," why bother?
>
> That said, I have in the past run across people who still have old
> e-mail addresses that they no longer have access to on their keys, so
> it's more than a theoretical issue, for me at least.

I see. So your procedure is to check that the name on the key matches
some ID, and THEN check separately that the key at least appears to
control the email addresses it claims.

Which does make a certain sense, I can see. :-)

Thank you for explaining.

Best wishes,

Nicholas

_______________________________________________
Gnupg-users mailing list
[email protected]
http://lists.gnupg.org/mailman/listinfo/gnupg-users

Reply via email to