[Enigmail] Setting trust levels for unknown keys
Andy Ruddock
andy.ruddock at rainydayz.org
Wed Apr 29 13:44:23 PDT 2009
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
John Clizbe wrote:
> Andy Ruddock wrote:
>> In the OpenPGP Kay Management window I select a new keys and
>> right-click and select "Set Owner Trust", which gives me five
>> options, the first two of which are "I don't know" and "I do NOT
>> trust".
>>
>> For these unknown keys I generally select "I don't know", but I
>> could also choose "I do NOT trust" as I have no knowledge of the
>> person or how the key was generated or is used. The "I do NOT
>> trust" option seems, to me, to be negative. If a scale were to be
>> drawn it seems to me that the "I don't know" option" would be at
>> the origin, with "I do NOT trust" at -1 and the other options at +1
>> and above.
>>
>> I wonder how other people use these settings.
>
> If I don't know the purported key owner I select "I don't know."
>
> "Don't know" is the zero option in this case. It's neutral.
>
> As Olav pointed out, "I do NOT trust." is for keys that should NEVER
> be trusted.
That's as I understood it - maybe the text should be a little stronger,
actually saying something along the lines of "Untrustworthy or known to
be bad"
- --
Andy Ruddock
- ------------
andy.ruddock at rainydayz.org (GPG Key ID 0xA622D452)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iEYEARECAAYFAkn4vCIACgkQfSkWkaYi1FIABwCeJBhkxO1ZnM8fS38j3Rl0kh5G
nLYAoKLTZ9xODOxrB7v76uWI0SAHV/8q
=6c/v
-----END PGP SIGNATURE-----
More information about the Enigmail
mailing list