Re disclaimers:
I still contend that it is easier to forge my signature with a biro
than to steal my secret to my Public key.
Re DN debate:
If you just want uniqueness then any DN will do, the certificate
serial number and issuer define a unique item.
Re registration:
Personally I would use the term register, when I send off my cert
to be signed by a CA. The verb to register and the noun a register
are different.
The current specs are usable for alot of applications, and most of the nit
picking seems to be really about applications that are as yet unspecified.
As someone has said, "Pem should be usable as a filter" It is just one
component. There are lots of applications where PEM is just not suitable
but it would have been nice to be able to use it.
Pete.