John,
The last set of PEM WG minutes included an appendix that
provided some top level analysis on why DNs are peferable to DNS names
for certificates. I'll forward a paper to you that provides a more
detailed discussion of the topic. If you attend the security session
at INE93 on Wednesday at the Hyatt Embarcadero I'll have some slides
too.
Steve
P.S. The concerns Bob Jueneman raises about binding info into names
in certificates would be even more difficult to address if we had to
use DNS names, since they don't have attribute tags, are more limited
in size and characterset, ...