opensubscriber
   Find in this group all groups
 
Unknown more information…

e : enigmail@mozdev.org 29 March 2012 • 9:42PM -0400

Re: [Enigmail] Enigmail level automatic key receiving from keyserver.
by Jean-David Beyer

REPLY TO AUTHOR
 
REPLY TO GROUP




-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Mika Suomalainen wrote:
> Hi,
>
> I was just wondering is it possible for Enigmail to automatically
> receive missing public keys from keyserver?

I may be (I do not know), but why would you want this? It seems to me
that for each key you put on your key ring you would want to verify is
valid and belongs to the person issuing it.

I could make up a key and say I was Barak Obama, send it to a key
server, and start signing stuff with it. If you receive something from
me signed with this bogus key, how would you know I was not the
president of the USA? Assuming he is your friend, you could call him and
compare his valid key fingerprint with the one you actually got from me,
and they would not be the same, so you would then know mine is a fake.
Just getting my bogus key from a keyserver would tell you nothing. Do
you really want a lot of bogus keys on your key ring?


- --
  .~.  Jean-David Beyer          Registered Linux User 85642.
  /V\  PGP-Key: 9A2FC99A         Registered Machine   241939.
/( )\ Shrewsbury, New Jersey    http://counter.li.org
^^-^^ 09:35:01 up 21 days, 18:16, 3 users, load average: 5.42, 5.42, 5.17
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)
Comment: Using GnuPG with CentOS - http://enigmail.mozdev.org/

iD8DBQFPdGawPtu2XpovyZoRAnNoAKCXXTAeztscF63J0sv3w0AO1z6AdACfdaWT
TEDALEN97BBoMRp/dTEoALI=
=xRxw
-----END PGP SIGNATURE-----
_______________________________________________
Enigmail mailing list
Enigmail@mozd...
https://www.mozdev.org/mailman/listinfo/enigmail

Bookmark with:

Delicious   Digg   reddit   Facebook   StumbleUpon

Related Messages

opensubscriber is not affiliated with the authors of this message nor responsible for its content.