You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
the presence of signatures is taken as a signal for subkey (in)validity. However, I think the signatures have not been cryptographically verified at that point.
Whatever amount of checking and filtering is done in that module, it might be surprising to some users. We should probably decide (and document) what semantics the signed_key module aims for. (I don't have a concrete suggestion, for now, but I hope to arrive at one, some day 😅)
The text was updated successfully, but these errors were encountered:
E.g. in
rpgp/src/composed/signed_key/public.rs
Lines 85 to 92 in 017be15
Whatever amount of checking and filtering is done in that module, it might be surprising to some users. We should probably decide (and document) what semantics the
signed_key
module aims for. (I don't have a concrete suggestion, for now, but I hope to arrive at one, some day 😅)The text was updated successfully, but these errors were encountered: