Brad> If someone in my employ uses PEM for work, I want to be assured that
when that person leaves her job, work related messages for her will be
readable by the person who assumes her job.
The keys used in such a situation are not for a _person_ but rather for
a _position_. I suppose it follows that one should use different
DN's and hence different e-mail addresses for personal vs work related mail.
You better do more than that, you had better not even put her name in
the DN, nor let her have any access to the plaintext of the private component,
nor ever let her use the key for ANY personal messages, or you are very likely
to see lawyers all around you.
Peace ..