Hi folks-- I'd like to propose that GnuPG only prompt the user for a "Comment" for their User ID under --expert mode.
Here's why: * most people just need a simple identity-driven OpenPGP certificate, one that matches their name and e-mail address. * new users see the prompt and think they need to enter something there, without understanding why or what to put there. This leads to people either making a witticism (e.g. "No Comment"), repeating their actual name, redundantly describing their e-mail address (e.g. "gmail address"), or saying something like "this is cool software", which then becomes part of their User ID and goes on the keyservers, associated with them permanently. When keysigning, if i get asked to certify a key with a "comment" like this, i don't know what to say. What am i certifying if i say that this key really belongs to "Joe Schmoe (no comment) <j...@example.org>" ? "Joe Schmoe <j...@example.org>" i can understand and certify, but the intervening comment doesn't seem sensible or verifiable. There are indeed some possibly legitimate uses of comments, but many of them would be better handled with notations attached to subkeys or notations attached to particular user IDs. What do other people think? If moving the Comment: prompt to --expert seems to radical, a more conservative proposal would be to change the prompt from: Comment: to: Comment (leave blank unless you are sure you need this and know what you are doing): or: Comment (most people should leave this blank): The example User ID prompt should also be changed (in english) from > You need a user ID to identify your key; the software constructs the user ID > from the Real Name, Comment and Email Address in this form: > "Heinrich Heine (Der Dichter) <heinri...@duesseldorf.de>" to: > Your new key needs a User ID that identifies you; Usually, this takes > the form of your real name followed by your e-mail address: > "Heinrich Heine <heinri...@duesseldorf.de>" Regards, --dkg
signature.asc
Description: OpenPGP digital signature
_______________________________________________ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users