If Peter is correct about CMP -- the EE can reject the cert after the CA signs it -- then I do not see we CANNOT have "neverValid." /r$