Several questions as feedback on gnupg

Loic Bernable
Wed Jan 23 20:02:01 2002

> There are two different trust values.  The one you are talking about
> here is the "owner trust".  It tells GnuPG how well you trust the
> owner of that key to sign other keys.  Nobody can change their own
> owner trust without walking up to your computer and doing it - it is
> not part of the key.

I know, but an end user computer can never be as secure as we want.
That's the reason of the existence of the passphrase, right ?=20

If you locally sign a key, it will also remain local to your computer,
but you are still asked for the passphrase. The question was to know why
there wasn't a verification of the identity of the person modifying the
trust DB. Is there a specific reason, except to make things easier ?

