Sure, but does that help? A very effective way to solve the "uniqueness problem" would be to append a sufficiently long random string to the name before signing it, but would that help in practice? When does attesting to my email address tell the person using the public key what they need to know?
Re: "PKI needs more than a name"
Date: 2002-06-11 04:06 am (UTC)