Trusted Signatures on your Public key?

Marc Mutz
Thu Jul 19 18:34:01 2001

On Thursday 19 July 2001 14:34, Huels, Ralf SCORE wrote:

> > You may additionally send an encrypted "ping" message to all UIDs
> > on the peer's key before signing just to make sure that the peer is
> > in fact in control of all UIDs and has the secret key.
> I usually sign only the UIDs represented on the paper fingerprint.
> This makes the signing process somewhat more complicated, but I don't
> have to worry about the other UIDs.
<snip> Yes, this is also advisable. However, I can come along and add Marc Mutz <> to my list of UIDs and - given such a user (e.g. Micheal Mutz) exists, and he hasn't got a PGP key on the keyserver (yet), my key is produced on a search. It comes down hoe 'hard' you personal certification policy is. Some certify onlt the name part and don't care about the mail addresses (e.g. c't pgpCA) and others (e.g. P. Palfrader) check the mail addresses, too. Marc