Bob,
The suggestion I made for adding an "ID number "attribute for
use in DN has nothing to do with the 1992/3 X.500 spec addition of the
unique ID fields. Those fields are NOT part of the DN, only part of
the certificate. Those new fields would help deal with the serial time
uniqueness issue IF you didn't already have an employee ID number.
The problem of how to trace back to a PCA has been discussed
previously and the use of the new Issuer UID field would make the job
trivial, even though we have other less efficient or less elegant
means available now.
Steve