Once again, reviewing documents for the first time in a while; apologies if
this is OBE, but:
The CERT draft, section 2.2, first sentence, says "Receiving agents MUST
support PKIX V1 and PKIX v3 certificates..."
There are no PKIX v1 certificates. (This looks like an artifact of a
global replacement X.509 -> PKIX.) Recommend that this be changed to
"Receiving agents MUST support PKIX certificates..." unless there is some
other type of certificates that you want to support (say, for backward
compatibility with S/MIMEv2). If there is such a type of certificates,
please identify it.
Al Arsenault
-- these are my opinions only. They do not necessarily reflect the
opinions of my employer, or of any other organization with which I have a
relationship.