I suggest the following paragraph be appended to section 4: A server which does not have a certificate installed and which does not support any anonymous ciphers SHOULD NOT advertise the STARTTLS keyword as it is not currently able to negotiate the use of TLS.
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature