>Summary: let's allow arbitrary *-forms, and only compute the
>	intersection of certificate chains when either
>		(a) at least one element of the chain is *-free, or
>		(b) the result is otherwise seen to be manageable in size.

agreed.  It's easy enough, even with 5-tuple engines that want to expand 
everything when it arrives to have them refuse to do cross products...on the 
theory that if a real request ever comes up, it will be a non-* form and 
will therefore reduce to a proper non-* result through the whole chain.

