In talking with Kent(?) Crispin (sp?)* after the SPKI BOF, he convinced me
of a solution to the "to allow or not allow delegation".  Since my problem
with the feature, is truth in advertising, rather than its presence in the
draft, we may be able to simply rename the problem away.

We now have it named and described in relation to what a certificate holder
(one whose public key was signed by an authority) can do with the
certificate.  If instead, we name it and describe it in terms of what the
verifier will do with the certificate, we are not implying that there is
protection against other forms of delegation.

One possibility would be to call it "Final".  (This name makes more sense
if the value is boolean rather than integer.)  If the value is integer, it
could be called something like MaxChainLength.  (You can see I've been
writing far too much Java code. :-) )

The description would be something like the maximum length of the chain of
certificates utilizing this certificate for authority which the verifier
will accept.

