I've noticed that RSA broke from the DN subordination requirement with its
residential CA (Unaffiliated User Certification Authority).
Now, TIS has done the same.
I understand the rationale, technical, political and otherwise, behind this
as opposed to having layers of CAs tied to geographical locales or
having the CA's DN appear in the name...
But this is a divergent implementation. With just RSA's UUCA, I satisfied
myself with saying "This is the exception, not the rule." But with TIS
joining the bandwagon, it appears to be the prevalent practice.
Now seems to be the time to appropriately bring the prevalent practice
and the standard into sync. so implementers like myself know how to handle
this case.
-Ray