Hi all,

Could someone please explain what the --export/import-ownertrust commands
actually do?  I have a colleague who is basically using it to exchange
key fingerprints - i.e. if Alice wants to tell her copy of GPG that
Bob's key is valid, then she gets Bob to run gpg --export-ownertrust,
send her the output file, and she then runs gpg --import-ownertrust on
that file.

I've searched on the net, but I can't find much about what the
--export/import-ownertrust do, beyond what is in the manpage.  What is
actually stored in this exported ownertrust database?

More importantly, I suspect that this is a bad thing to do.  What
problems does it cause?


