aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorWerner Koch <[email protected]>2017-03-08 09:46:09 +0000
committerWerner Koch <[email protected]>2017-03-08 10:35:53 +0000
commitf0257b4a86b73f5b956028e68590b6d2a23ea4da (patch)
tree546bb6004484a48f558f09cfeae5b3d15fef6c5e
parentRevert "build: Improve CFLAGS handling." (diff)
downloadgnupg-f0257b4a86b73f5b956028e68590b6d2a23ea4da.tar.gz
gnupg-f0257b4a86b73f5b956028e68590b6d2a23ea4da.zip
doc: Add a note to the trust model direct.
* doc/gpg.texi (GPG Configuration Options): Add note. Chnage Index from trust-mode:foo to trust-model:foo.
Diffstat (limited to '')
-rw-r--r--doc/gpg.texi20
1 files changed, 12 insertions, 8 deletions
diff --git a/doc/gpg.texi b/doc/gpg.texi
index 55482b1a8..0e107ecb5 100644
--- a/doc/gpg.texi
+++ b/doc/gpg.texi
@@ -1608,17 +1608,17 @@ Set what trust model GnuPG should follow. The models are:
@table @asis
@item pgp
- @opindex trust-mode:pgp
+ @opindex trust-model:pgp
This is the Web of Trust combined with trust signatures as used in PGP
5.x and later. This is the default trust model when creating a new
trust database.
@item classic
- @opindex trust-mode:classic
+ @opindex trust-model:classic
This is the standard Web of Trust as introduced by PGP 2.
@item tofu
- @opindex trust-mode:tofu
+ @opindex trust-model:tofu
@anchor{trust-model-tofu}
TOFU stands for Trust On First Use. In this trust model, the first
time a key is seen, it is memorized. If later another key is seen
@@ -1664,7 +1664,7 @@ Set what trust model GnuPG should follow. The models are:
@code{undefined} trust level is returned.
@item tofu+pgp
- @opindex trust-mode:tofu+pgp
+ @opindex trust-model:tofu+pgp
This trust model combines TOFU with the Web of Trust. This is done
by computing the trust level for each model and then taking the
maximum trust level where the trust levels are ordered as follows:
@@ -1677,12 +1677,16 @@ Set what trust model GnuPG should follow. The models are:
which some security-conscious users don't like.
@item direct
- @opindex trust-mode:direct
+ @opindex trust-model:direct
Key validity is set directly by the user and not calculated via the
- Web of Trust.
+ Web of Trust. This model is soley based on the key and does
+ not distinguish user IDs. Note that when changing to another trust
+ model the trust values assigned to a key are transformed into
+ ownertrust values, which also indicate how you trust the owner of
+ the key to sign other keys.
@item always
- @opindex trust-mode:always
+ @opindex trust-model:always
Skip key validation and assume that used keys are always fully
valid. You generally won't use this unless you are using some
external validation scheme. This option also suppresses the
@@ -1692,7 +1696,7 @@ Set what trust model GnuPG should follow. The models are:
disabled keys.
@item auto
- @opindex trust-mode:auto
+ @opindex trust-model:auto
Select the trust model depending on whatever the internal trust
database says. This is the default model if such a database already
exists.