I was wondering if the best system to build a global PKI wouldn't be the
DNS system already in place?
This is an ongoing argument. Essentially there are two camps:
Pro--there's a global database out there, let's put useful stuff
into it. Certs is a no-brainer, but people have also argued for
baseball scores, usernames, and everything else short of kitchen
sink inventories.
Just FYI: the Kitchen Sink RR has been proposed...
--Johnny