Brian --

...and then Brian Clark said...
% * David T-G ([EMAIL PROTECTED]) [Jan 24. 2002 10:00]:
% > ...and then Brian Clark said...
% > % I was trying to get something similar to work yesterday. No one
% > % finds it odd that one can't check a single signature? I've given
% > I think it's becoming a more common request, but in the past it's been
% > pretty typical to either verify all or care about none. We just have
% > to evolve :-)
% OK, maybe I'm not getting something about GnuPG and/or Mutt's
% interaction with GnuPG, then (Nope, not being sarcastic here). If I set

Fair enough.

% this thing to verify all signatures, and I have my keyserver settings in
% place, every single key that I verify is being added to my keyring. Is
% this not undesirable by most people? 

I can hardly fathom it :-) but that's how I'm set up.

My understanding, contrary to Jeremy's probably-quite-accurate argument
of file size and key management in general (thank heavens for gpg and
multiple keyrings instead of monolithic pgp!), is that folks don't want
to wait for gpg to run for [approaching] every message, much less take
the time to download the key from a server -- which only works if one is
not queueing up mail while offline anyway.  I don't know how true my
understanding is, however.  It seems to me (IMHO) that you'd want
verification always off when offline and on when online, and I'd drive
that by making $pgp_verify_command a shell script which checks my
connection state before deciding to run or not.

% -- 
% Brian Clark | Avoiding the general public since 1805!
% Fingerprint: 07CE FA37 8DF6 A109 8119 076B B5A2 E5FB E4D0 C7C8
% It may be your sole purpose in life to serve as a warning to others.

David T-G                      * It's easier to fight for one's principles
(play) [EMAIL PROTECTED] * than to live up to them. -- fortune cookie
(work) [EMAIL PROTECTED]    Shpx gur Pbzzhavpngvbaf Qrprapl Npg!

Attachment: msg23743/pgp00000.pgp
Description: PGP signature

Reply via email to