RE: spec for wire format of SPKI cert

Thanks, Bill.  I now understand your point.  I think it gets back to an
earlier comment of Carl's about trusting the users.  My point has
always been that giving a privilege to a user implies complete trust
that the user will do what is appropriate with it.  What the user does
with it is his responsibility, but that is outside the scope of the
authorization system.  No security system can keep me from telling
someone inappropriately what I've learned appropriately, and I think
that's your point.  I sort of thought it went without saying; perhaps
not.  At minimum, it's important to remember it.


