Jeff,
The self-signed certificate option seems to be a common factor among most of
the deployed PEM implementations. If there is interest, I will post a
proposal for allowing a self-signed certificate in the
Originator-Certificate field, what the significance of the serial
number in this certificate would be, etc.
I think this would be helpful. I confess that I haven't
examined all of the proposals along this line in depth,
so perhaps you could review some of them and point
out their various strengths and weaknesses,
Bob