On 04/21/2017 09:48 AM, John C Klensin wrote:
In addition, as others have pointed out, if you can't trust your email (server) provider, then expecting others to trust keys on the basis that they are obtained from that server may not make a lot of sense.
You do not have to trust your or their email server. If you trust the cert issuer. Then use the result.
If you do not trust the cert issuer, then do not use the results. -- Doug Royer - (http://DougRoyer.US http://goo.gl/yrxJTu ) DouglasRoyer@xxxxxxxxx 714-989-6135
<<attachment: smime.p7s>>