Notes Plugin ini settings

Hi, could anyone advise whether setting the following ini parameter in the "plugin_customization.ini"file could be considered as a security loophole ( in terms) of opening up the client to unauthorised etc code/hacking/virus activity etc.

To use an external notes plugin, we are being asked to include the following setting in the ini file

For

Lotus\Notes\framework\rcp\plugin_customization.ini

add line

com.ibm.rcp.security.update/TRUST_CERTIFICATE_AUTHORITIES=true

the Reason given is that …

"because Notes doesn’t automatically trust the required certificate the plugin is signed with "

any advice appreciated