[pkg-gnupg-maint] Bug#933791: gnupg: please document the consequences of not accepting third-party certifications from keyservers

Francesco Poli invernomuto at paranoici.org
Mon Aug 5 09:20:33 BST 2019


On Sun, 4 Aug 2019 23:56:46 +0000 Georg Faerber wrote:

> Hi,

Hello Georg,
thanks for your comment!

[...]
> FWIW, caff provides an option which might help with this
[...]
> 
>   also-lsign-in-gnupghome [auto|ask|no]
>     
>     Whether to locally sign the UIDs in the user's GnuPGHOME, in
>     addition to caff's signatures in its own GnuPGHOME.

This is indeed potentially useful...

[...]
>     However, note that local signatures will not be deleted once the
>     recipient does the upload and the signer refreshes her keyring.

...although it does have its own downsides.


-- 
 http://www.inventati.org/frx/
 There's not a second to spare! To the laboratory!
..................................................... Francesco Poli .
 GnuPG key fpr == CA01 1147 9CD2 EFDF FB82  3925 3E1C 27E1 1F69 BFFE
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-gnupg-maint/attachments/20190805/7d739d04/attachment.sig>


More information about the pkg-gnupg-maint mailing list