Alan, > >In addition - who will own the root level key for all this PKIX >compliant stuff? PKIX does not assume any single root CA in its model. See section 6.1 of 2459 for its discussion of starting points for cert path validation. Steve