...
In addition to these two extremes (all versus none), there is a
number of variations where the dnq (DN Qualifier) does not apply to
all or none, but to *some* of the components of the DN. This would
solve other concerns raised on that thread.
All concepts could nicely co-exist if we could find a way to say on
*which* components of the DN the dnq (DN Qualifier) would apply.
Rather than leaving the interpretation to an (unprocessable)
Certificate Policy OID, we should define a way to express which
components of the RDN should be associated with the dnq to make the
name unmistakable and *permanently* unique.
I'm opposed to adding a notion of selective marking of RDNs to
indicate which ones, in concert, really qualify as a DN, remembering
the definition of a DN. This was the subject of a private message
exchange between Anders and me last week, so I'm happy to share my
thoughts on this topic.