Page MenuHome GnuPG

Draft: Kleopatra: certifications by available secret key which is *not* set to "ultimate" owner trust are disregarded
Open, NormalPublic

Description

When you import a secret key and answer the dialog widow with "No, its not my key", the owner trust will be set to unknown instead of ultimate.
If you then try to certify another key with it, it can be selected and the certify button is functional:

The only thing unusual for the user is the "is this your own key?" question.

When you click "Certify" you'll get the message that the certification was done.

But the certified public key isn't shown as certified in the certificate list aka keyring:


Although it is certified by the key in question, as can be seen in the certificate details.

Only after you set the ownertrust of that key to "ultimate" the certificate will be shown as "certified".

This is surprising for users ("I have signed that key, why is it not shown as certified?").

Is this what we want?
I can imagine that one would want to handle it this way (= to not trust the certifications of a shared key marked "not my own") but then I wonder if certification with it should not be allowed in Kleopatra, either.

More documentation to explain this would be good, in any case.

Event Timeline

ebo triaged this task as Normal priority.Fri, May 2, 3:21 PM
ebo created this task.