Vint> I cannot imagine that ISOC or the various PCAs would want to
inject themselves into the middle of lawsuits concerning the binding
nature of PEM transactions.
This could be very damaging to the whole concept of Digital Signature if
it were true. The only way I can imagine non-repudiation to work is for
the CA (PCA or whatever) to testify in court as an expert witness. If
this is excluded at this stage, then IMHO we are also excluding ANY
legal stature to the entire concept of Digital Signature. If the CA
(PCA) will not testify as to the process used to produce the signature,
then what value is the CA? What value has the CA added to the process?
I may as well use the "Web of Trust" PGP model for certificates.
Peace ..Tom Jones