KeyValidity is an OpenPGPConcept that relates to the ownership of keys.
Conceptually a key is valid if it is actually owned by the person who it purports to be owned by. Determining KeyValidity can be a complicated process and is usually expressed as ValidityTrust.
Technically GPG regards a key as valid in a keyring if:
When calculating trust, the OwnerTrust values are used to verify the validity of the key in question. A key if one of the following is true
The reasoning behind this is that if three, seperate people who you have marginal trust in have come to independent conclusions (after performing the Key Verification steps below), that the key is valid, you can trust it to be valid. And if someone you fully trust has determined a key to be valid, you can trust it as well. The number of fully trusted keys and marginally trusted keys required to determine validity of can be modified in the GPG configuration file.
To personally verify the validity of a key, you need to ensure that the public key belongs to the person who it purports to belong to. The OpenPGP standard purposefully does not define a trust model, or a definitive standard that should be used for determining ownership of a key. It is left up to the user to satisfy themselves that the key is correctly owned before signing it.
A suggested method of verifying the validity of a key is
Once you have verified the validity of a key you should sign it (see SigningAKey) to indicate that you trust it's validity. This helps to expand the WebOfTrust and increase the usefulness of the OpenPGP system
6 pages link to KeyValidity:
lib/main.php:944: Notice: PageInfo: Cannot find action page
lib/main.php:839: Notice: PageInfo: Unknown action