[wellylug] GPG Question

Jethro Carr jethro.carr at jedolinux.com
Thu Mar 2 19:26:18 NZDT 2006


On Thu, 2006-03-02 at 17:36 +1300, David Murray wrote:
> On Thu, 2 Mar 2006, Jonathan Harker wrote:
> 
> > Jethro Carr wrote:
> >> So say you signed "jethro.carr at jedolinux.com", if I changed my email to
> >> "jethro.carr at some_place_other_than_microsoft.com", your signature
> >> against my key would be "lost", as the signature was against the old
> >> email address/UID.
> >>
> >> does that make sense? :-/
> >
> > I understand exactly, I have same problem. I don't know either.  :-)

pity. :-(

that will teach me to change email addresses!

> Perhaps this is to ensure that the signature is for the one person at the 
> one email address, and for no other.
> 
> 
> Thus, if you want a new email address, you will need a new signature, and 
> people will need to again verify you are who you say you are.
> 
> That kinda makes sense to me, given that pgp signatures are intended to 
> ensure person to person communication.
> 
> Aren't they?

yes, but people often have more than 1 address.


-- 
Jethro Carr

www.jethrocarr.jedolinux.com
www.jethrocarr.jedolinux.com/index.php?page=cv/cv.php

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://lists.wellylug.org.nz/pipermail/wellylug/attachments/20060302/bb21de0c/attachment.pgp 


More information about the wellylug mailing list