key validity

The first ID draft proposes that the subject include not only the key but 
also a reference to a self-signed cert or on-line service the job of which 
is to show that the subject key is still valid.  A simple self-signed cert 
doesn't do any good.  If a key is stolen, the thief can self-sign validity 

The indirection mechanisms David and I discussed today can cover key 
invalidity.  They don't require any additional field alongside the Subject.  
Could it be that we can eliminate the Subject-info: field?


 - Carl

