Ed,
The lack of explicit means of expressing certification policies,
the lack of rigorous name space management, and the lack of a
certificate revocation architecture probably will hinder use of PGP in
the commercial environment. The Arpanet (really Internet today)/UUCP
analogy may be a reasonable one. Most commercial organizations I am
aware of are joining the Internet, with its global, unique address space
(which is managed by a central authority with regional delegation) and
with its global, unique domain name space (also reflecting a single root
with distributed, delegated management). I'm quite happy with that
analogy!
Steve