Michael Richardson wrote:
>   When you generate your "personal CA" key, you also generate your
> "daily use key" and you sign it, with the personal CA key, delegating
> (tag (*)) to it.

Problem:  Certs without delegation rights.

