Automatically accept OpenPGP public key (identities) that are signed with one of the user's personal keys
Categories
(MailNews Core :: Security: OpenPGP, enhancement)
Tracking
(Not tracked)
People
(Reporter: KaiE, Unassigned)
References
(Depends on 1 open bug)
Details
Alice has either one, or a set of, personal OpenPGP key(s) she has marked as her personal keys.
In the past, or on a different computer, or in a different Thunderbird profile, or using different software on the same computer, Alice might have used the "third party certification" feature of OpenPGP to sign Bob's public key. In my opinion, such a third party signature is equivalent to saying "I accept this key, I have verified myself that it is correct".
The suggestion is that Thunderbird should automatically look for such certifications from any of Alice's own personal keys, and automatically treat the key as accepted (verified) for the signed user IDs (email addresses).
(Clarification: Such certifications are per user ID. If Bob's key lists multiple user IDs, usually with separate email addresses, then Alice might have signed only a subset of the user IDs. The automatic acceptance should be limited to those email addresses.)
Description
•