Bob raised a very good point:
CAs are about registrations -- binding a name to an entity
Directories are about listings -- publicizing names
The purpose of my message is to separate these two different
mythologies.
/mtr
Marshall,
I am not sure I understand you. I think I read your first statement
to be that a CA is a naming authority ? That is not how a CA has
been viewed in the past. Surely it is the responsibility of the
Directory administrator to assign names ? I believe that the CA's
responsibility is limited to the relationship of the name holder and
that holder's public key ...
If it is generally held that the CA is a naming authority then
several things in PEM (and secure messaging in general) have
suddenly become easier.
Have I misread you ?
John