Re: GPG USAGE HOWTO 1 (was: Re: AM report on Thierry Bourrillon)
On Tue, Apr 17, 2001 at 12:48:24AM +0200, Peter Palfrader wrote:
> On Tue, 17 Apr 2001, Ralf Treinen wrote:
>
> > If I sign a key I confirm the fact that the person with the name on
> > the key has claimed to me that the key is his. IMHO my signature on
> > the key does not confirm that the person is owner of the mailbox.
> > Am I right?
>
> When I sign a key I confirm than
> o a person showing me a photo ID (passport, etc..) has claimed that
> this key (with fingerprint etc) is their key,
> o the Name on the photo ID matches the name on the key user id
> o the person can receive and read mail at all mailboxes I sign.
>
> I used to check whether the person actually owns the secret key too
> but don't do this any longer.
Everyone should do these. Guys, take those keys seriously, please :)
--
Lenart, Janos
<ocsi@debian.org>
Reply to: