Several questions as feedback on gnupg

Loic Bernable
Wed Jan 23 19:56:01 2002

> When validating the user ID you should validate the whole of the user
> ID, including the e-mail address portion.  Methods like showing that=20
> encrypted mail to the e-mail address in the UID can be read could be
> used.

So your advice should be to send an encrypted email to the person who
gave you his/her key, wait for his/her approval by email and *only* then
sign his/her key, right ?

The things get complicated :o)

