Rhys,
As you may have noticed, I'm trying to work backward through
my mail backlog for a change, hence the order of my responses.
Your observation about the university dilemma with student
certificates is not a good example, I think. A school can issue
certificates with validity intervals tied to expected matriculation
intervals. That way only those who drop out, graduate early, or
experience a possible compromise need to be put on the CRL.
As for adding the RIPEM documentation to PEM, I tried to
address that issue in my immediate, previous response.
With regard to getting PERSONA certificates, RSA is providing
just such a facility, without charge. So this concern is alreday
addressed.
Steve