Right. I did not say anything about "individuals" issuing cross certs. I referred to organizational CAs, e.g., certified by other such CAs, or by bridge CAs, etc.While I am not sure that Steve proposed that individuals issue cross-certs in his posting, I would like to record my view that allowing an RP to extend trust to a specific root CA with restrictions similar to the constraints extensions is a desirable feature in an API. Since IMHO this is basically an API issue, I'm not sure that it's within PKIX's scope.
Tom Gindin