Re: Light-weight certificate revocation lists ?

I pointed out some while ago on another list that SSL
is very well suited to the issuance of short-term
or ephemeral certificates.

It would seem, to be practical for a moment, a simple
task to make a SSL implementation which used full-blown
identity certs for its first highly public handshake,
then immediately perform a second handshake under the
negotiated confidentiality service in which both peers exchange 
SPKI/SDSI certs with a view to "re"-establishing the private
trust model, agree the reduction algebra and, where necessary,
represent its processing rules programmatically, and then perform 
the authorization decision.

Such ephemeral certs convey authorization data in the auth field,
and said fields may be programmatic representations of the
data (e.g. another little java applet) which inherently conveys the
necessary rules to perform whichever reduction algebra
is declared by the auth-field tag(s), for the authorization system(s)
agreed upon by conforming SPKI/SDSI cert validating systems.

To gauge whether Im getting into the SPKI/SDSI spirit, is such
a simple working concept way off course as an example
practical insertion into the existing Internet security
infrastructure of SPKI/SDSI certs?

