I'm flexible about this, depending on what the community wants.
It would complicate CRL processing, becuase some entries might
be pending and thus would require that one make subsequent
passes or be able to mark cache entries with future revocation
times.
I think we should stick with the intent of the directory standard.
Another problem with allowing future dates to be specified is it begs
the question of synchronized clocks; there is a significant
simplification in testing only for membership on the list.
Jim