1) Is there a flexibility contained in the MIME/PEM or general
MIME specifications which I'm missing.
2) If not, is it important to try to incorporate such
flexibility into the approach, especially if wider applicability
(beyond messaging) of the draft is intended. (note: I think
this question is closely tied to the object security
requirements question?)
In response to your first question, yes. The purpose of the security
multiparts document is to allow for the specification of alternative
signature (and encryption) schemes. We've defined exactly one in the
PEM and MIME document, which we've labeled "application/pem-signature".
Jim