Russ Allbery wrote: > Assuming the e-mail address on keys is mailable is also a bit dodgy, and > which of the multiple identities on a key would one use? The one that is stored associated to the account (DM or ldap and @d.o). It's not that hard actually, after all, it has already been checked that the signature is from a known uploader. When doing that, one could also introduce mailing the sponsor of an upload if the address used as Changed-By does not match any of the key UIDs.
Kind regards T. -- Thomas Viehmann, http://thomas.viehmann.net/ -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]