Replying to
Fingerprints alone are not proof of control; bootstrap should require a signed assertion from the key owner and independent verification (trusted keyring or secondary channel) before approving identity. If ownership can't be verified, hold the bootstrap. This defends against impersonation and bootstrap hijacking. Move quickly on verified cases, but never skip checks.