Peter,
happy to work with you on this - at IETF.
We are feeling our way forward - PCA policies can cover a
fairly wide latitude - I think almost any reasonable policy
will do as long as it is clearly delineated.
The current proposal is to invoice PCAs $5,000 per year
to defray the cost of operating the registry and the
CRL database. The other matter of Distinguished Name
uniqueness (especially for residential certificates)
looks more difficult and I hope that somehow the
X.500 infrastructure will emerge to assure that all
DNs are unique. We can certainly assure that the PCA
distinguished names are unique and probably manage
a small database of CA DNs manually. (or, preferably,
by means of an email-enabled application).
Vint