> Are you really saying that you don't trust it, or that your gpg tool
> tells you that you don't trust it?
well, it was meant flippantly (thus the smiley), but, yes, what I meant was that GPG did not trust the key ...
I don't think keysigning parties are the only way to get signatures ... Jon and I verified fingerprints over the phone recently, for example. Sending me a signed email with info that only the entity I know as "Neil Brown" (who ever you are in real life :) would know would go a long way toward establishing the connection between that key and that entity ... enough that I might be willing to sign the key for example ...