Well, we seem to have a split of opinion. On the one hand, we have a
set of people who say we need:
o bottom up trust and/or a broader trust models, with the 1422
hierarchy serving as just one of a set of mechanisms
o email based identification as the basis, with other identifiers,
e.g. DNs, as auxiliary identifiers
On the other hand we have a set of people saying the current design is
right and we should stay the course.
More or less a level below these main concerns are issues like
separation of encryption from signature, integration of MIME and PEM,
choices of algorithms, etc.
Is this reconcilable within this WG? If not, then perhaps we should
subdivide our concerns.
Maybe this is a time for others to express themselves too.
Steve